Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
CI/CD
Distributed Systems @ 6
GPU @ 4
HPC
Kubernetes @ 4
Linux @ 4
SRE @ 8
Security @ 8
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
NVIDIA DGX Cloud is an AI Factory designed to power the next generation of AI and industrial-scale breakthroughs. As a Principal Engineer for Security Architecture within the Security Engineering organization, you will own a core security domain of the AI factory, including its architecture, paved road, and much of the underlying code. You will help establish the security design bar across DGX Cloud while working directly with the engineering teams building the platform. This is a founding position on a new team.
Security Engineering is a new DGX Cloud organization accountable for the platform's security outcomes. Security Architecture holds the design bar across the platform, working horizontally across the fleet and vertically across the stack. You will embed with teams building GPU clusters, control planes, and services, participating in their designs rather than acting as an approval gate. You will help build systems in which entire classes of risk are no longer possible.
Responsibilities
- Take end-to-end architectural ownership of a core DGX Cloud security domain, from design through production. Potential domains include tenant and GPU workload isolation, workload identity, infrastructure and network security, supply-chain provenance, hardened baselines and patching, or deploy-time policy and admission control.
- Join designs early, write code, and help engineering teams deliver secure systems.
- Build paved roads that make the secure path the easiest path for platform teams to adopt.
- Engineer classes of risk out of existence by improving systems and paved roads rather than relying only on vulnerability findings or requirements.
- Run deep-dive threat models across the substrate, orchestration layer, and tenancy boundary.
- Review designs offensively, incorporate findings into baselines, guardrails, and detections, and help close architectural gaps.
- Translate the DGX Cloud security bar into reference architectures, requirements, and golden paths.
- Partner with DGX Cloud platform, production engineering, network security, and NVIDIA's central security organization.
- Help implement the secure path in CI/CD and across the hardware lifecycle.
- Work horizontally across vertically organized teams through influence, credibility, and collaboration rather than formal authority.
Requirements
- Typically 15+ years of experience across software engineering, SRE, infrastructure, and security engineering.
- Strong software engineering background with the ability to write clean, maintainable, well-tested code.
- Experience building and operating production services at scale.
- Experience working with emerging technologies, including reviewing AI-generated code, applying AI-assisted analysis to security engineering, and building for agents operating inside owned systems.
- Experience designing, deploying, and operating security architecture in areas such as multi-tenant isolation, identity and access, policy enforcement, vulnerability management, or detection engineering.
- Proven ability to build threat models for complex distributed systems, identify architectural gaps, and engineer solutions that address them.
- Experience with cloud-native architecture, container orchestration, and Kubernetes.
- Hands-on Linux systems security experience, including kernel-level primitives such as eBPF, AppArmor, or SELinux.
- Experience landing designs through teams you do not own, using credibility and relationships to drive execution.
- Bachelor's degree in Computer Science, Engineering, or a related technical field, or equivalent experience, with 15+ years of relevant experience.
Preferred Qualifications
- Experience securing high-performance computing environments, RDMA-based networks, large GPU fleets, or GPU-specific systems.
- Expertise in workload identity frameworks such as SPIFFE/SPIRE, hardware root of trust including TPM/HSM integration, or confidential computing.
- Real exploitation, red team, or security research experience translated into engineering controls, guardrails, and detections.
- Notable contributions to security-focused open-source projects or a track record of engineering-focused security research.
NVIDIA is leading developments in artificial intelligence, high-performance computing, and visualization. The company offers equity and benefits in addition to the base salary. Applications will be accepted at least until September 25, 2026. NVIDIA uses AI tools in its recruiting processes and is an equal opportunity employer.