Cloud Infrastructure Security Engineer (Systems/Kernel)

Runpod
$152,000 - $175,000Remote

About The Position

Runpod is seeking an innovative security engineer who thrives at the systems layer. You will operate with an Attacker's Mindset, actively hunting for ways to break container and virtualization boundaries, and then writing the low-level code to patch them. As RunPod continues to revolutionize the GPU cloud computing landscape, we are seeking a systems-focused Cloud Infrastructure Security Engineer. This critical position is instrumental in safeguarding our bare-metal and virtualized environments, ensuring the absolute security, multi tenant isolation, and integrity of our underlying GPU cloud infrastructure. The ideal candidate possesses deep knowledge of Linux systems, kernel internals, hypervisors, and containerization. You will focus on the lowest levels of our stack—preventing tenant breakouts, securing GPU hardware allocations, and building resilient infrastructure to support AI and machine learning workloads.

Requirements

  • 5+ years of experience in infrastructure or systems-level security engineering.
  • Extensive knowledge of Linux kernel internals (cgroups, namespaces, eBPF, SELinux/AppArmor).
  • Deep understanding of virtualization technologies (KVM, QEMU) and workload/network isolation techniques in multitenant environments.
  • Strong systems-level programming skills in C, Go, Rust, or Python.
  • Familiarity with GPU architecture and hardware-level security considerations.
  • Experience in securing bare-metal cloud infrastructure and mitigating lower-level CVEs.

Nice To Haves

  • Contributions to open-source systems security projects or virtualization research.
  • Experience writing or deploying eBPF-based security tooling.
  • Deep knowledge of low-level networking protocols and virtualized network security.

Responsibilities

  • Systems Isolation: Design and implement robust workload and network isolation architectures for RunPod's multitenant GPU bare-metal and virtualized environments.
  • Kernel & Container Security: Harden Linux kernel configurations, container runtimes (e.g., Docker, containerd), and orchestration layers (e.g., Kubernetes) against breakouts and privilege escalation.
  • Infrastructure Threat Modeling: Conduct deep-dive security assessments and penetration testing specifically targeting our hypervisor, network stack, and hardware interfaces.
  • Active Defense: Write code (primarily C, Go, or Rust) to implement custom security controls, telemetry, and fixes at the OS and infrastructure level.
  • Hardware Security: Evaluate and mitigate security considerations specific to GPU architecture, PCIe pass-through, and shared memory spaces.
  • Incident Response: Serve as the technical escalation point for infrastructure-level security incidents, developing forensic capabilities for ephemeral container environments.

Benefits

  • Competitive base pay for this position ranges from ($152,000 - $175,000).
  • Meaningful equity in a fast-growing company - everyone on the team receives stock options.
  • Generous medical, dental & vision plans
  • Flexible PTO
  • Remote work first with an inclusive, collaborative teams utilizing slack as the main form of internal communication
  • $1,200 Home Office & Equipment Stipend
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service