The opportunity
Crusoe is on a mission to accelerate the abundance of energy and intelligence . As the only vertically integrated AI infrastructure company built from the ground up, we own and operate each layer of the stack — from electrons to tokens — to power the world's most ambitious AI workloads.
What you'll do
Kernel Hardening & CVE Triage: Implement kernel security enhancements, manage configuration hardening, and triage incoming CVEs to assess severity and exploitability.
Access Control, Boot Security & Guardrails: Enforce mandatory access controls, secure the boot path, and establish CI guardrails and fuzzing coverage to prevent regressions.
Vulnerability Research & Analysis: Research vulnerabilities across kernel, driver, and OS components to build proactive mitigations and backport non-trivial upstream fixes to production.
Secure Development Practices: Establish and advocate for secure coding standards and best practices for kernel-level development. Conduct security-focused code reviews to identify and eliminate potential vulnerabilities early in the development lifecycle.
Security Auditing & Tools: Utilize and develop specialized tools for kernel security auditing, fuzzing, static analysis, and dynamic analysis to uncover hidden vulnerabilities and ensure compliance with security policies.
Incident Response Support: Provide expert support during security incidents involving kernel or OS-level compromises, assisting with root-cause analysis, containment, and recovery efforts.
What they're looking for
- Performance and Security Balance: Work to ensure that security enhancements do not unduly impact system performance, especially critical for our high-performance AI infrastructure.
- First 90 days: Own kernel CVE triage end to end and have shipped at least one backported fix through our full release path. You have an independent read on where our kernel configuration is weakest.
- First year: Kernel security response has a defined SLA by severity and we: consistently hit it. A hardening baseline is defined, enforced in CI, and rolled out across supported SKUs. Cloud Hypervisor has been audited and the highest-value isolation gaps are closed or scheduled.
- Cloud Hypervisor & Isolation: Audit, harden, and reduce privilege across Cloud Hypervisor device models and vhost-user datapaths, contributing upstream security fixes and advancing confidential computing primitives (AMD SEV-SNP, Intel TDX).