The opportunity
Runpod is the AI Developer Cloud. More than one million developers, from indie researchers to teams running frontier models in production, use Runpod to experiment, train, fine-tune, deploy, and scale AI on one platform.
What you'll do
Systems Isolation: Design and implement robust workload and network isolation architectures for RunPod's multitenant GPU bare-metal and virtualized environments.
Kernel & Container Security: Harden Linux kernel configurations, container runtimes (e.g., Docker, containerd), and orchestration layers (e.g., Kubernetes) against breakouts and privilege escalation.
Infrastructure Threat Modeling: Conduct deep-dive security assessments and penetration testing specifically targeting our hypervisor, network stack, and hardware interfaces.
Active Defense: Write code (primarily C, Go, or Rust) to implement custom security controls, telemetry, and fixes at the OS and infrastructure level.
Hardware Security: Evaluate and mitigate security considerations specific to GPU architecture, PCIe pass-through, and shared memory spaces.
Incident Response: Serve as the technical escalation point for infrastructure-level security incidents, developing forensic capabilities for ephemeral container environments.
What they're looking for
- + years of experience in infrastructure or systems-level security engineering.
- Extensive knowledge of Linux kernel internals (cgroups, namespaces, eBPF, SELinux/AppArmor).
- Deep understanding of virtualization technologies (KVM, QEMU) and: workload/network isolation techniques in multitenant environments.
- Strong systems-level programming skills in C, Go, Rust, or Python.