Jobs › Companies › xAI › Infrastructure Security Engineer (Bare Metal & Platform)

Über diese Infrastructure Security Engineer (Bare Metal & Platform) Stelle bei xAI

xAI · Hybrid · Palo Alto, CA; Austin, TX; New York, NY; Seattle, WA

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.

ABOUT THE ROLE:

We are seeking a hands-on Infrastructure Security Engineer to build and secure SpaceXAI’s infrastructure from the bare-metal layer up through the platform and application stack. In this role, you will design, implement, and harden physical and private-cloud foundations—servers, networks, identity, and orchestration—and carry that security posture into containers, automation, and hybrid connectivity with public cloud.

This role focuses on securing critical infrastructure spanning data centers, colo, and hybrid environments, with work that may span platforms such as SpaceXAI, X Social, X Money, and related systems. You’ll operate with an automation-first mindset: building secure foundations at the metal and OS layer, hardening platforms at scale, and partnering closely with engineering so security is embedded in how we build and run systems—not bolted on after the fact.

RESPONSIBILITIES:

Bare metal, data center & network security

  • Design and implement secure bare-metal and private-cloud architectures (servers, storage, out-of-band management, BIOS/UEFI/BMC firmware posture)
  • Harden physical and virtual fleets: OS baselines (Linux/Windows), CIS benchmarks, patch and vulnerability management, and secure boot / measured boot where applicable
  • Hands-on firmware, BMC/iDRAC/iLO, PXE/Kickstart provisioning, and hardware lifecycle security
  • Build and secure network foundations: segmentation, load balancers, DNS, PKI, NAC, and IDS/IPS on real hardware
  • Own hybrid connectivity between on-premises and cloud (site-to-site VPN, Direct Connect / Interconnect / ExpressRoute, SD-WAN, zero-trust access)
  • Manage identities and privileged access across Active Directory / LDAP / Kerberos and cloud IAM (federation, SAML/OIDC, PAM)
  • Assist with security assessments and audits of physical, on-premises, and hybrid infrastructure
  • Monitor and remediate infrastructure to comply with regulations and best practices (e.g., PCI, NIST CSF, GDPR, HIPAA)

Platform, containers & developer enablement

  • Design and implement secure container and Kubernetes standards on bare metal and private cloud (not only managed EKS/GKE/AKS), including RBAC, network policy, and secrets
  • Develop and maintain Infrastructure as Code and configuration management—especially Puppet—with embedded security controls for physical and virtual fleets
  • Collaborate with development teams so security best practices are integrated into CI/CD pipelines
  • Secure and enhance CI/CD pipelines; integrate and maintain code and image scanning platforms

Detection, operations & tooling

  • Monitor and respond to security events and incidents spanning bare metal, network devices, hosts, and hybrid cloud
  • Maintain SIEM data pipelines that ingest on-premises network, host, and cloud telemetry for reliable alerting
  • Build, deploy, and maintain security operations infrastructure using Python, Terraform, and Puppet
  • Develop dashboards and alerts from security metrics across physical and platform layers
  • Develop and maintain infrastructure security policies, standards, and procedures from metal through platform
  • Own security projects end to end: identify issues and implement solutions
  • Stay current with emerging threats and mitigations for bare-metal, firmware, network, and hybrid-cloud infrastructure

BASIC QUALIFICATIONS:

  • Bachelor's degree in Computer Science, Cybersecurity, or a related field
  • 3–5 years of experience in infrastructure security, platform security, or related hands-on roles
  • Proven experience securing bare-metal, data-center, or private-cloud environments (not cloud-only resumes)
  • Hands-on experience with firmware, BMC/iDRAC/iLO, PXE/Kickstart provisioning, and hardware lifecycle security
  • Strong proficiency with Puppet for configuration management and fleet hardening in production
  • Strong understanding of network security concepts and protocols, including hands-on work with firewalls, segmentation, and hybrid connectivity
  • Experience with hybrid identity (AD/LDAP or similar) integrated or federated with cloud IAM
  • Experience with Infrastructure as Code (e.g., Terraform) applied to physical or VM fleets
  • Familiarity with containerization and Kubernetes security implications, including on-premises or bare-metal clusters
  • Experience with languages (e.g., Python, Bash and Golang) for automation and tool development
  • Familiarity with regulatory compliance requirements (e.g., GDPR, HIPAA, PCI DSS, NIST CSF)
  • Experience in banking, money transmission, P2P payments, or similarly regulated financial platforms
  • Proactive mindset with strong ownership, critical thinking, and problem-solving skills
  • Located in the SF Bay Area, Austin, New York, Palo Alto, or Seattle, or willing to relocate to a US office

PREFERRED SKILLS AND EXPERIENCE:

  • Deep expertise operating and securing physical server fleets, colo, or private cloud (VMware, OpenStack, Proxmox, Nutanix, or similar)
  • Relevant security certifications (e.g., CCSP, CSSK, OSCP, network or cloud security specialty)
  • Strong proficiency with Python and Terraform on production fleets
  • Deep expertise in Kubernetes and container security on bare metal or private cloud
  • Experience with multi-cloud and cloud-to-on-prem security
  • Knowledge of CI/CD best practices and tools; hands-on GitHub Actions or equivalent
  • Experience with observability and security operations tooling (e.g., Prometheus, Grafana, CloudWatch, Karma; SIEM platforms such as Wazuh)
  • Experience building custom security tools or integrations
  • Interest in leveraging AI for infrastructure security monitoring and automation
  • Contributions to open-source infrastructure or security projects
  • Experience securing AI/ML and GPU workloads on bare metal or hybrid infrastructure

COMPENSATION AND BENEFITS:

$100,000 - $258,000 USD

Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.

SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.

Bereit, sich bei xAI zu bewerben?
Bei xAI bewerben

Wie sich dieses Gehalt für Security Engineer vergleicht

Diese Stelle zahlt $179,000/yr — im Einklang mit der üblichen Spanne für Security Engineer Stellen.

$105,000 dem Median $172,915 $254,948

Übliche Spanne $136,983–$210,900/yr, aus 1,658 vergleichbaren Security Engineer Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Security Engineer ansehen →

Ähnliche Jobs

xAI
Infrastructure Security Engineer
xAI
⚡ Früh bewerben Palo Alto, CA; Austin, TX; Ne... Vor Ort $100,000–$258,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.
RE
Security Engineer, Platform
Resend
⚡ Früh bewerben Europe · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 21 Min.
RE
Security Engineer, Platform
Resend
⚡ Früh bewerben Americas · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 21 Min.
January
Senior Security Engineer
January
⚡ Früh bewerben New York City Hybrid $200,000–$231,000
● Neu 👁 Gesehen ✓ Beworben vor 26 Min.
Hadrian Automation
Security Engineer, Full Stack
Hadrian Automation
⚡ Früh bewerben Seattle/Bellevue Area, WA Vor Ort $160,000–$230,000
● Neu 👁 Gesehen ✓ Beworben vor 27 Min.
Megaport
Security Engineer
Megaport
⚡ Früh bewerben Sao Paulo Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 44 Min.
Esri
Sr. Application Security Engineer
Esri
⚡ Früh bewerben Vienna, Virginia, United State... Vor Ort $93,600–$157,560
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.
Esri
Sr. Application Security Engineer
Esri
⚡ Früh bewerben Redlands, CA Vor Ort $93,600–$157,560
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.
TraceLink, Inc
Product Security Engineer, Senior
TraceLink, Inc
⚡ Früh bewerben APAC - India - Pune Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 2 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei xAI

Alle Jobs bei xAI ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos