Sr. Staff Platform Security Engineer, Cloud Infrastructure
✨ AI Summary
Groq, an AI inference platform company, is hiring a Sr. Staff Platform Security Engineer to lead security architecture for cloud infrastructure. The role focuses on identity and access, Kubernetes security, and multi-tenant isolation using Go, Python, and GitOps. Candidates require 6+ years of experience in software engineering with deep expertise in cloud security and distributed systems.
Mission:
Build and scale the security foundations that enable customers to run sensitive AI workloads with confidence on Groq's inference platform. You will set technical direction and build critical security capabilities across identity and access, Kubernetes, multi-tenant infrastructure, secrets, encryption, and key and certificate management. As a senior software engineer and technical leader, you will partner across Platform Engineering to turn complex security requirements into durable, automated systems that scale with the platform.
Location: We prioritize hiring in or near the SF Bay Area, New York City and Dallas.
Responsibilities & opportunities in this role:
- Set technical direction and own the architecture for critical platform security capabilities across identity, authorization, infrastructure security, encryption, key management, and auditability.
- Design and build identity and access systems spanning authentication, federation, authorization, workload identity, lifecycle provisioning, and administrative access.
- Build and scale security capabilities for Kubernetes and other distributed infrastructure using software, policy, automation, APIs, controllers, Infrastructure-as-Code, and GitOps.
- Architect security controls and isolation mechanisms for multi-tenant systems across compute, network, storage, and control-plane boundaries.
- Own infrastructure lifecycle security, including secure provisioning, secrets and credential management, encryption, and certificate lifecycle.
- Build production software and automation that make secure infrastructure patterns reliable, scalable, and easy for engineering teams to adopt.
- Lead security-sensitive platform designs and changes, translating complex risks and requirements into practical engineering decisions and scalable platform capabilities.
- Shape security architecture and technical standards across Platform Engineering, influencing designs beyond the systems you directly own.
- Partner across engineering and security to build capabilities that strengthen customer trust, platform reliability, and support compliance requirements.
- Clearly communicate security architecture, technical tradeoffs, and risk to engineers, technical leaders, and security leadership.
Ideal candidates have/are:
- 6+ years of software engineering experience building complex infrastructure or distributed systems, with deep experience in cloud and platform security, identity and access, Kubernetes, or related infrastructure security domains.
- Demonstrated experience setting technical direction and owning complex security architecture across multiple systems, teams, or infrastructure domains.
- Deep experience with identity and access technologies such as OIDC, SAML, SCIM, RBAC, workload identity, short-lived credentials, and multi-factor authentication.
- Deep experience designing security for multi-tenant systems and isolation across network, compute, storage, and control-plane boundaries.
- Hands-on Kubernetes security expertise, including RBAC, admission control, service-account and workload identity, secrets and encryption, policy enforcement, and node security.
- Strong understanding of secrets management, encryption, key management, certificate lifecycle, and secure credential management.
- Strong software engineering skills in Go, Python, or similar languages, with experience designing, building, and operating production systems.
- A software-first approach to security, with experience building controls through APIs, controllers, automation, policy, Infrastructure-as-Code, GitOps, or similar approaches.
- Experience leading ambiguous, cross-functional technical initiatives and influencing engineering direction across teams.
- Ability to reason about complex security systems end to end and communicate technical risk and architectural tradeoffs clearly to different audiences.
- Experience building identity, key-management, network security, or infrastructure security capabilities for cloud platforms is valuable.
- Experience with network policy and encryption or security for high-performance storage and distributed infrastructure is valuable.
- Experience translating security and compliance requirements into automated evidence and production-ready controls is valuable.
- Experience building Kubernetes operators, admission webhooks, or similar infrastructure automation is valuable.
Why Join Us
- Purposeful Hiring: You’re not here by accident, and neither is anyone else. Every teammate is handpicked with intention because who we build with matters.
- Builders Wanted: You’re not just riding the rocket ship, you’re building it. Your work directly shapes the trajectory of our company.
- Mission-Driven Work: We’re here to make a real impact. Our mission fuels everything we do.
- Tackling Hard Problems: If easy isn’t your thing, you’re in the right place. We solve some of the most complex and exciting challenges in our space.
- Excellence Is The Standard: High performance isn’t just encouraged, it’s the baseline. And it’s contagious.
If this sounds like you, we’d love to hear from you!
Compensation
Groq is committed to providing competitive compensation through our Total Cash philosophy, which incorporates potential bonus value directly into base pay. The total cash salary range for this position, which is inclusive of the potential bonus value, is $341,400 - $401,600, with individual placement determined by your geographic location, experience, skills, and alignment with internal compensation standards. This range is specific to candidates located in the United States. Compensation for international candidates will vary based on local market dynamics. Beyond cash compensation, Groq also offers a Long-Term Incentive (LTI) Program and a robust suite of employee benefits.
US Job Posting
This position may require access to technology and/or information subject to U.S. export control laws and regulations, including the Export Administration Regulations (EAR). To comply with these requirements, candidates for this role must meet certain citizenship or residency criteria. Specifically, they must qualify as U.S. Persons for export control purposes (i.e., U.S. citizen, U.S. lawful permanent resident (Green Card holder), or a protected individual under 8 U.S.C. § 1324b(a)(3) such as a refugee or asylee), or otherwise be eligible for an applicable export license.
#LI-MS1
About the Company
More jobs at Groq
-
Sr./Staff Forward Deployed Engineer
· hybrid · Oct 2, 2026