Staff Kernel Security Engineer
Crusoe · San Francisco, CA - US
About this role
## Staff Kernel Security Engineer ### About Crusoe Crusoe is on a mission to accelerate the abundance of energy and intelligence. As a vertically integrated AI infrastructure company, we own and operate each layer of the stack—from electrons to tokens—to power the world’s most ambitious AI workloads. ### About the Role Crusoe’s Cloud Software Development team is seeking a **passionate and experienced Staff Software Engineer specializing in Linux Kernel Security**. This role is critical to strengthening the security posture of our core **Linux kernel and operating system components** that underpin our AI cloud hardware and software solutions. This is a **full-time** position. ### What You’ll Be Working On - **Kernel Hardening & CVE Triage:** Implement kernel security enhancements, manage configuration hardening, and triage incoming CVEs for severity and exploitability. - **Access Control, Boot Security & Guardrails:** Enforce mandatory access controls, secure the boot path, and establish CI guardrails and fuzzing coverage to prevent regressions. - **Vulnerability Research & Analysis:** Research vulnerabilities across kernel, driver, and OS components; build proactive mitigations and backport non-trivial upstream fixes to production. - **Secure Development Practices:** Establish and advocate for secure coding standards; conduct security-focused code reviews to eliminate vulnerabilities early. - **Security Auditing & Tools:** Use and develop tools for kernel security auditing, fuzzing, static analysis, and dynamic analysis to uncover hidden vulnerabilities and ensure compliance. - **Incident Response Support:** Support security incidents involving kernel/OS-level compromises, including root-cause analysis, containment, and recovery. - **Performance and Security Balance:** Ensure security enhancements don’t unduly impact performance—especially for high-performance AI infrastructure. - **Cloud Hypervisor & Isolation:** Audit, harden, and reduce privilege across Cloud Hypervisor device models and vhost-user datapaths; contribute upstream security fixes and advance confidential computing primitives (AMD SEV-SNP, Intel TDX). - **Cross-Functional Collaboration:** Partner with hardware, hypervisor, OS development, cloud infrastructure, and security operations teams to deliver a comprehensive security strategy. - **Technical Leadership:** Mentor junior engineers and foster a culture of security awareness and excellence. - **Debugging & Root-Cause Analysis:** Debug and root-cause complex security issues at the kernel level. ### First 90 Days - Own **kernel CVE triage end to end** and ship at least **one backported fix** through the full release path. - Develop an independent read on where kernel configuration is weakest. ### First Year - Maintain a defined **kernel security response SLA by severity**. - Define, enforce in CI, and roll out a **hardening baseline** across supported SKUs. - Ensure **Cloud Hypervisor** has been audited and highest-value isolation gaps are closed or scheduled. ### What You’ll Bring to the Team - **Linux Kernel Security Expertise:** Deep knowledge of Linux kernel internals (memory management, scheduling, syscalls, I/O subsystems) with a security focus. - **Vulnerability & Exploitation Knowledge:** Understanding of common kernel vulnerabilities (privilege escalation, info disclosure, DoS) and exploitation techniques. - **Security Mitigations:** Experience with Linux mitigations such as ASLR, DEP/NX, SMEP/SMAP, KASL
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.