Relocantly← All jobs

🇮🇹 Milan, Italy · 16h ago

Security Engineering Lead

Stealth Startup

LinkedInleadEnglish-friendly
Apply on LinkedIn →Get jobs like this daily
About UsWe are an early-stage technology company operating at the intersection of Energy and AI infrastructure, focused on developing a new generation of efficient and scalable computing infrastructure.Our approach combines distributed computing, modular infrastructure and energy efficiency to support the rapidly growing demand for AI and high-performance computing.The company is developing a new model for deploying compute capacity in a flexible and scalable way, with a strong focus on efficiency, sustainability, reliability and responsible infrastructure development.This is an opportunity to join a growing team at an early stage and contribute directly to the development of a new infrastructure platform, working at the intersection of power, data centers and advanced computing.Position TypeFounding member of the Security function, initially reporting to the Head of SoftwareRole OverviewWe are seeking a Security Engineering Lead to own the security posture and compliance of our self-contained, outdoor-deployable AI/HPC compute systems and the meshed clusters they form. This is a founding security role: you will define the end-to-end security of the product and be hands-on building it, before growing and helping lead the security function as the company scales. The role spans three connected worlds: platform and infrastructure security (a sovereign Kubernetes/Talos GPU cloud), product and system security (physical units deployed in the field), and compliance and governance (a sovereign, multi-tenant offering operating under EU regulation). We do not expect deep mastery of every security domain on day one: we are looking for someone with a holistic security vision and a proven ability to lead through security crises, excellent in at least one core domain and with the appetite and ability to grow into the others.What You Will DeliverThis is a high-impact, high-ownership role. You will define how our systems protect their tenants, their data, and themselves, and your security architecture will ship across every unit and cluster we deploy.Within 6 months: You will own and deliver the security architecture of the first compute system prototype: a documented threat model of the system and mesh, hardened Talos/Kubernetes baselines, the identity, secrets and PKI foundations, a tenant-isolation model, and a first detection and incident-response capability validated in the lab. This means driving security technology selection, making key design decisions, and working hands-on to secure the platform and the software supply chain (signed images, SBOM) in our GitOps pipeline.Within 12 months: You will own the security posture of the first production-ready product: an industrialized, defense-in-depth platform with proven multi-tenant isolation and secure wipe between tenants, and the compliance groundwork laid and ready for our first certification. Working closely with network, software, and hardware colleagues, you will deliver a security architecture that is documented, automated, auditable, and ready to scale into series deployment, and you will begin setting the standards and practices for a growing security team.Key ResponsibilitiesOwn the end-to-end security posture and threat model of the system and meshed cluster, across product/system, platform, identity, data, and inter-site securityDefine and implement defense-in-depth for the Kubernetes/Talos platform: node and cluster hardening (CIS benchmarks), admission control (OPA/Kyverno), runtime security (e.g. Falco), and NetworkPoliciesOwn identity, secrets, and PKI: OIDC single sign-on and RBAC, secrets management (e.g. Vault), an internal PKI, and key/certificate lifecycle (HSM where required)Guarantee multi-tenant isolation: workload isolation across VMs and containers (KubeVirt, MIG), encryption, secure wipe between tenants, and attestationStand up detection and incident response: security logging and SIEM, alerting, playbooks, and lead security crisis management end to endSecure the software supply chain: SBOM, image signing (cosign/sigstore), dependency and infrastructure-as-code scanning, and secure GitOps practicesOwn security compliance and governance: drive the information security management system and the sovereignty roadmap (ISO/IEC 27001, SecNumCloud, NIS2/GDPR and EU-cloud alignment), including policies, risk management, and audit readinessContribute to product and system security together with the hardware team: secure boot, TPM/measured boot and attestation, supply-chain integrity, and hardening of deployed unitsCollaborate closely with network (segmentation, zero-trust, mesh), software, and hardware colleagues, and produce security architecture documents, threat models, and operational runbooksSet security standards and practices as the function grows, with a path to build and help lead a small security teamRequirementsBachelor’s degree in Computer Science, Engineering, Cybersecurity, or equivalent field7-12 years of hands-on security experience in cloud/infrastructure, platform, or product security, including time in a lead or leadership roleA proven holistic security vision and a demonstrated ability to lead and manage security incidents and crises end to endHands-on experience contributing to the implementation of at least one recognized framework, ISO/IEC 27001, SecNumCloud (ANSSI), or NIS2/GDPR and EU-cloud regulation, with a solid command of its requirementsDeep expertise in at least one of: (a) cloud-native/Kubernetes platform hardening, (b) identity, secrets and PKI, or (c) multi-tenant workload isolation, with the appetite and ability to grow into the othersStrong foundations in detection and response and in software supply-chain securityAbility to work in a fast-paced, early-stage environment with a high degree of ownership and autonomyEnglish speakingNice to HaveExperience securing sovereign, multi-tenant, or otherwise regulated cloud/infrastructureProduct or system security and hardware-integration security: secure boot, TPM/measured boot and attestation, and confidential computingHands-on with cloud-native security tooling (e.g. Falco/Tetragon, OPA/Kyverno, Vault, cosign/sigstore, Trivy)Familiarity with the target stack (Talos Linux, Cilium, KubeVirt, Ceph, GitOps/FluxCD)Familiarity with zero-trust networking and network segmentation for multi-tenant infrastructurePrior experience at a hardware or infrastructure startup or scale-up, where scope and pace require broad ownershipLocation Milan, Italy. hybrid

Sourced from LinkedIn. Relocantly aggregates public job postings; apply on the original site.