Skip to content

Open nowPosted yesterday

Senior Staff Linux Security Engineer — Crusoe

Felicis portfolio1,392 open roles

Pay
$250,000 – $300,000 a year
Where
Sunnyvale, California, United States; Sunnyvale, CA - US
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Staff Linux Security Engineer — CrusoeFelicis portfolio · Sunnyvale, California, United States; Sunnyvale, CA - US
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Felicis portfolio's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Felicis portfolio postings stay open a median of 29 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.0%30 days
This job: posted yesterday

Felicis portfolio median: 29 days open

The posting

Crusoe is on a mission to accelerate the abundance of energy and intelligence. As the only vertically integrated AI infrastructure company built from the ground up, we own and operate each layer of the stack — from electrons to tokens — to power the world's most ambitious AI workloads. When you join Crusoe, you join a team that is building the future, faster.

We're in the midst of the greatest industrial revolution of our time. The demand for AI compute is boundless, and power is a bottleneck. We're solving that — with an energy-first approach that makes AI infrastructure better for the world and faster for the people innovating with AI.

We're looking for problem-solving, opportunity-finding teammates with a sense of urgency, who believe in the scale of our ambition and thrive on a path not fully paved — people who want to grow their careers alongside a team of experts across energy, manufacturing, data center construction, and cloud services.

If you want to do the most meaningful work of your career, help our customers and partners advance their AI strategies, and be part of a high-performing team that believes in each other, come build with us at Crusoe.

About the Role:

The Crusoe Cloud Software Development team is seeking a passionate and experienced Senior Staff Software Engineer specializing in Linux Kernel Security. This critical role is essential in strengthening the security posture of our core Linux kernel and operating system components, which underpin our cutting-edge hardware and software solutions for the AI cloud. A deep understanding of Linux kernel internals, security vulnerabilities, mitigation techniques, and secure development practices is paramount for developing reliable, high-assurance systems. This is a full-time position.

What You'll Be Working On:

  • Kernel Hardening & CVE Triage: Implement kernel security enhancements, manage configuration hardening, and triage incoming CVEs to assess severity and exploitability.
  • Access Control, Boot Security & Guardrails: Enforce mandatory access controls, secure the boot path, and establish CI guardrails and fuzzing coverage to prevent regressions.
  • Vulnerability Research & Analysis: Research vulnerabilities across kernel, driver, and OS components to build proactive mitigations and backport non-trivial upstream fixes to production.
  • Secure Development Practices: Establish and advocate for secure coding standards and best practices for kernel-level development. Conduct security-focused code reviews to identify and eliminate potential vulnerabilities early in the development lifecycle.
  • Security Auditing & Tools: Utilize and develop specialized tools for kernel security auditing, fuzzing, static analysis, and dynamic analysis to uncover hidden vulnerabilities and ensure compliance with security policies.
  • Incident Response Support: Provide expert support during security incidents involving kernel or OS-level compromises, assisting with root-cause analysis, containment, and recovery efforts.
  • Performance and Security Balance: Work to ensure that security enhancements do not unduly impact system performance, especially critical for our high-performance AI infrastructure.
  • First 90 days: Own kernel CVE triage end to end and have shipped at least one backported fix through our full release path. You have an independent read on where our kernel configuration is weakest.
  • First year: Kernel security response has a defined SLA by severity and we consistently hit it. A hardening baseline is defined, enforced in CI, and rolled out across supported SKUs. Cloud Hypervisor has been audited and the highest-value isolation gaps are closed or scheduled.
  • Cloud Hypervisor & Isolation: Audit, harden, and reduce privilege across Cloud Hypervisor device models and vhost-user datapaths, contributing upstream security fixes and advancing confidential computing primitives (AMD SEV-SNP, Intel TDX).
  • Cross-Functional Collaboration: Collaborate closely with other engineering teams (hardware, hypervisor, OS development, cloud infrastructure, and security operations) to integrate security best practices and ensure a comprehensive security strategy across the stack.
  • Technical Leadership: Provide technical guidance and mentorship to junior engineers on kernel security best practices, fostering a culture of security awareness and excellence.
  • Debugging and Root-Cause Analysis: Debug and root-cause a variety of complex security-related issues at the kernel level.

What You'll Bring to the Team:

  • Linux Kernel Security Expertise: Proven deep knowledge of Linux kernel internals (e.g., memory management, process scheduling, system calls, I/O subsystems) with a strong focus on security aspects.
  • Vulnerability & Exploitation Knowledge: Solid understanding of common kernel vulnerabilities (e.g., privilege escalation, information disclosure, denial of service) and associated exploitation techniques.
  • Security Mitigations: Experience with existing Linux kernel security mitigations (e.g., ASLR, DEP/NX, SMEP/SMAP, KASLR, namespaces, cgroups, LSMs like SELinux/AppArmor).
  • Secure Coding: Strong background in secure coding principles and experience conducting security-focused code reviews, particularly in C.
  • Debugging & Analysis Tools: Proficiency with kernel debugging tools (e.g., GDB, crash, kgdb) and security analysis tools (e.g., valgrind, address sanitizers, fuzzers).
  • Hardware Security Concepts: Familiarity with hardware-assisted security features (e.g., Intel SGX, AMD SEV, ARM TrustZone) and their relevance to kernel security.
  • Education & Experience: Bachelor's degree in Computer Science, Computer Engineering, or a related field, and a minimum of 5 years of relevant industry experience with at least 3 years focused on low-level operating systems or kernel security.
  • Safety and Compliance: Must be able to pass a background check.
  • Company Values: Embody the Company values.
  • Experience dealing with CVE Remediation and automation
  • First 90 days: You own kernel CVE triage end to end and have shipped at least one backported fix through our full release path. You have an independent read on where our kernel configuration is weakest.
  • First year: Kernel security response has a defined SLA by severity and we consistently hit it. A hardening baseline is defined, enforced in CI, and rolled out across supported SKUs. Cloud Hypervisor has been audited and the highest-value isolation gaps are closed or scheduled.

Bonus Points

  • Experience with specific kernel security projects or contributions to open-source kernel security initiatives.
  • Familiarity with hypervisor security and the interaction between the hypervisor and the guest kernel's security.
  • Experience with hardware security modules (HSMs) or Trusted Platform Modules (TPMs).
  • Background in offensive security or penetration testing at the kernel level.

Benefits:

  • Competitive compensation and equity packages
  • Restricted Stock Units
  • Paid time off, paid holidays & leave of absence programs
  • Comprehensive health, dental & vision insurance
  • Employer contributions to HSA account
  • Paid parental leave
  • Paid life insurance, short-term and long-term disability
  • Professional development & tuition reimbursement
  • Mental health & wellness support
  • Commuter benefits (parking & transit)
  • Cell phone stipend
  • 401(k) Retirement plan with company match up to 4% of salary
  • Volunteer time off
  • Global travel insurance & emergency assistance
  • Daily meals allowance
  • Additional perks & programs specific to location

Compensation Range

Compensation will be paid in the range of up to $250,000 - $300,000 + Bonus. Restricted Stock Units are included in all offers. Compensation to be determined by the applicant's knowledge, education, and abilities, as well as internal equity and alignment with market data.

Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Felicis portfolio's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Felicis portfolio's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Felicis portfolio's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.