4 hours ago

Director, Infrastructure Security

Crusoe

San Francisco, CaliforniaUnited States

📍 On-site

Category: SecuritySubcategory: Security EngineerType: Full-time


Crusoe is on a mission to accelerate the abundance of energy and intelligence. As the only vertically integrated AI infrastructure company built from the ground up, we own and operate each layer of the stack — from electrons to tokens — to power the world's most ambitious AI workloads. When you join Crusoe, you join a team that is building the future, faster.

We're in the midst of the greatest industrial revolution of our time. The demand for AI compute is boundless, and power is a bottleneck. We're solving that — with an energy-first approach that makes AI infrastructure better for the world and faster for the people innovating with AI.

We're looking for problem-solving, opportunity-finding teammates with a sense of urgency, who believe in the scale of our ambition and thrive on a path not fully paved — people who want to grow their careers alongside a team of experts across energy, manufacturing, data center construction, and cloud services.

If you want to do the most meaningful work of your career, help our customers and partners advance their AI strategies, and be part of a high-performing team that believes in each other, come build with us at Crusoe.

About the Role:

As a GPU-cloud provider, Crusoe’s infrastructure is our product. Infrastructure Security Engineering is arguably the most critical domain in our security engineering organization.

Unlike traditional enterprise cloud security functions that act as passive auditors asking other teams to fix bugs, this is an elite engineering and software development organization. You will lead a dedicated team of 5–6 infrastructure security engineers who design, build, and operate foundational security layers across our hyper-scale fleet.

This role offers a high-impact organizational leadership opportunity: guiding an established team of talented engineers, sharpening technical focus, streamlining delivery, and instilling a high-velocity software delivery culture to build an elite, world-class engineering unit.

Reporting directly to the Senior Director of Security Engineering, you will own two core pillars: Platform Security Engineering and Infrastructure Security Access and Posture Management.

What You'll Be Working On:

1. Team Leadership & Talent Elevation

  • Organizational Leadership: Lead, mentor, and empower a team of 5–6 infrastructure security engineers. Optimize delivery processes and elevate the team into a high-throughput engineering organization.

  • Engineering Rigor & Velocity: Transition the team to a proactive platform engineering model with clear shipping cadences, code quality standards, and architectural roadmaps.

  • Strategic Growth & Hiring: Establish clear accountability and strategically hire additional engineering talent to complement existing strengths in systems security and automation.

2. Platform Core Security Services (Foundational Engineering)

  • Identity, Secrets & PKI: Build, operate, and scale core identity and crypto primitives, including workload identity (SPIFFE/SPIRE), enterprise secrets-as-a-service (HashiCorp Vault), and public key infrastructure (PKI) across multi-tenant GPU environments.

  • Fleet Telemetry & eBPF: Deploy and manage eBPF-based security sensors at scale across bare-metal and virtualized fleets to deliver high-fidelity observability and kernel-level runtime protection.

  • Fleet Access & Just-In-Time (JIT): Architect and enforce zero-trust, JIT access mechanisms for engineers and operators accessing fleet nodes, hypervisors, and core switches.

  • Firmware & Supply Chain Security: Build mechanisms for secure boot, hardware roots of trust, firmware update delivery, and software supply chain verification across GPU nodes, CPUs, and network fabrics.

  • Infrastructure Vulnerability Management: Build platforms to continuously track, prioritize, and remediate vulnerability states across millions of bare-metal, containerized, and hypervisor assets.

3. Infrastructure Security Posture & IAM (Architecture & De-risking)

  • Control Plane & Cloud Security: Secure Crusoe’s multi-layer control plane across public cloud environments (GCP) and multi-gigawatt on-premise AI data center infrastructure.

  • IAM & Elimination of Standing Secrets: Eliminate standing admin privileges and long-lived secrets. Architect least-privilege RBAC/ABAC models across cloud projects and physical infrastructure.

  • Architectural Isolation & Risk Reduction: Identify and eliminate systemic architectural risks (e.g., decoupling co-mingled Terraform execution environments, isolating tenant control planes, and establishing hard boundary enforcement across GCP projects and GPU clusters).

  • Security Architecture & Governance-by-Code: Perform continuous security architecture reviews, enforcing change management, isolation, and baseline posture natively through IaC (Terraform, OpenTofu, Kubernetes operators).

What You'll Bring to the Team:

  • Platform & Security Engineering Leadership: 8+ years leading and scaling software or security engineering teams at hyper-scale cloud providers (AWS, GCP, Azure, OCI) or infrastructure-intensive platforms. Must have led builder-focused teams that delivered core platform security functionality and software systems at scale.

  • Engineering Leadership & Mentorship: Demonstrated success leading engineering teams, streamlining execution, fostering high-performance team cultures, and raising the technical bar.

  • Hands-on Builder Experience: Proven track record of shipping core security platforms (Vault, SPIFFE/SPIRE, eBPF sensors, JIT access engines) rather than managing third-party posture management tools (CSPM).

  • Deep Architectural De-risking: Ability to dissect complex cloud/on-prem deployment architectures, isolate blast radiuses, and eliminate co-mingled execution risks.

  • Technical Depth: Deep comprehension of Linux kernel security, container runtimes (Kubernetes), IAM frameworks, PKI, and lower-level hardware/network primitives (GPUs, switches, bare-metal orchestrators).

  • Location: In-person / Hybrid presence in the San Francisco Bay Area to build deep technical partnerships across engineering leadership.

Benefits:

Competitive compensation and equity packages

Restricted Stock Units

Paid time off, paid holidays & leave of absence programs

Comprehensive health, dental & vision insurance

Employer contributions to HSA account

Paid parental leave

Paid life insurance, short-term and long-term disability

Professional development & tuition reimbursement

Mental health & wellness support

Commuter benefits (parking & transit)

Cell phone stipend

401(k) Retirement plan with company match up to 4% of salary

Volunteer time off

Global travel insurance & emergency assistance

Daily meals allowance

Additional perks & programs specific to location

Compensation Range

Compensation will be paid in the range of up to $285,000 - $335,000 + Bonus. Restricted Stock Units are included in all offers. Compensation to be determined by the applicant's knowledge, education, and abilities, as well as internal equity and alignment with market data.

Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.

Share This Job

Apply for this position

Interested? Click below to submit your application.

Apply to this job