Staff Kernel Security Engineer

$215k - $260k • San Francisco, CA - US • FullTime

Posted 3h ago

Remote Work Policy

On-site

Employment Type

FullTime

Categories

LLM Engineer

About the job

Crusoe is seeking a Staff Software Engineer specializing in Linux Kernel Security to strengthen the security of our core Linux kernel and operating system components. This role is crucial for our AI cloud infrastructure, requiring a deep understanding of kernel internals, security vulnerabilities, and mitigation techniques. You will be responsible for implementing security enhancements, triaging CVEs, enforcing access controls, researching vulnerabilities, and advocating for secure development practices. The position involves auditing and hardening Cloud Hypervisor, collaborating with cross-functional teams, and providing technical leadership. This is a full-time position focused on building a secure and high-performance AI infrastructure.

Responsibilities

  • Implement kernel security enhancements and manage configuration hardening.
  • Triage incoming CVEs to assess severity and exploitability.
  • Enforce mandatory access controls and secure the boot path.
  • Establish CI guardrails and fuzzing coverage to prevent regressions.
  • Research vulnerabilities across kernel, driver, and OS components.
  • Develop proactive mitigations and backport upstream fixes.
  • Establish and advocate for secure coding standards and best practices.
  • Conduct security-focused code reviews.
  • Utilize and develop tools for kernel security auditing, fuzzing, static analysis, and dynamic analysis.
  • Provide expert support during security incidents involving kernel or OS-level compromises.
  • Ensure security enhancements do not unduly impact system performance.
  • Audit, harden, and reduce privilege across Cloud Hypervisor device models and vhost-user datapaths.
  • Contribute upstream security fixes and advance confidential computing primitives.
  • Collaborate with other engineering teams to integrate security best practices.
  • Provide technical guidance and mentorship to junior engineers on kernel security.
  • Debug and root-cause complex security-related issues at the kernel level.

Requirements

  • Deep knowledge of Linux kernel internals (memory management, process scheduling, system calls, I/O subsystems) with a focus on security.
  • Solid understanding of common kernel vulnerabilities and associated exploitation techniques.
  • Experience with existing Linux kernel security mitigations (e.g., ASLR, DEP/NX, SMEP/SMAP, KASLR, namespaces, cgroups, LSMs).
  • Strong background in secure coding principles and experience conducting security-focused code reviews, particularly in C.
  • Proficiency with kernel debugging tools (e.g., GDB, crash, kgdb) and security analysis tools (e.g., valgrind, address sanitizers, fuzzers).
  • Familiarity with hardware-assisted security features (e.g., Intel SGX, AMD SEV, ARM TrustZone).
  • Bachelor's degree in Computer Science, Computer Engineering, or a related field.
  • Minimum of 5 years of relevant industry experience, with at least 3 years focused on low-level operating systems or kernel security.
  • Ability to pass a background check.

About crusoe

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.