Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI
API @ 4
Compliance @ 4
Distributed Systems @ 7
Go @ 7
Kubernetes @ 7
Python @ 7
Security @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Mission
Build and scale the security foundations that enable customers to run sensitive AI workloads with confidence on Groq's inference platform. Set technical direction and build critical security capabilities across identity and access, Kubernetes, multi-tenant infrastructure, secrets, encryption, and key and certificate management. Partner across Platform Engineering to turn complex security requirements into durable, automated systems that scale with the platform.
Responsibilities
- Set technical direction and own the architecture for critical platform security capabilities across identity, authorization, infrastructure security, encryption, key management, and auditability.
- Design and build identity and access systems spanning authentication, federation, authorization, workload identity, lifecycle provisioning, and administrative access.
- Build and scale security capabilities for Kubernetes and other distributed infrastructure using software, policy, automation, APIs, controllers, Infrastructure-as-Code, and GitOps.
- Architect security controls and isolation mechanisms for multi-tenant systems across compute, network, storage, and control-plane boundaries.
- Own infrastructure lifecycle security, including secure provisioning, secrets and credential management, encryption, and certificate lifecycle.
- Build production software and automation that make secure infrastructure patterns reliable, scalable, and easy for engineering teams to adopt.
- Lead security-sensitive platform designs and changes, translating complex risks and requirements into practical engineering decisions and scalable platform capabilities.
- Shape security architecture and technical standards across Platform Engineering, influencing designs beyond the systems directly owned.
- Partner across engineering and security to build capabilities that strengthen customer trust, platform reliability, and support compliance requirements.
- Clearly communicate security architecture, technical tradeoffs, and risk to engineers, technical leaders, and security leadership.
Requirements
- 6+ years of software engineering experience building complex infrastructure or distributed systems, with deep experience in cloud and platform security, identity and access, Kubernetes, or related infrastructure security domains.
- Demonstrated experience setting technical direction and owning complex security architecture across multiple systems, teams, or infrastructure domains.
- Deep experience with identity and access technologies such as OIDC, SAML, SCIM, RBAC, workload identity, short-lived credentials, and multi-factor authentication.
- Deep experience designing security for multi-tenant systems and isolation across network, compute, storage, and control-plane boundaries.
- Hands-on Kubernetes security expertise, including RBAC, admission control, service-account and workload identity, secrets and encryption, policy enforcement, and node security.
- Strong understanding of secrets management, encryption, key management, certificate lifecycle, and secure credential management.
- Strong software engineering skills in Go, Python, or similar languages, with experience designing, building, and operating production systems.
- A software-first approach to security, with experience building controls through APIs, controllers, automation, policy, Infrastructure-as-Code, GitOps, or similar approaches.
- Experience leading ambiguous, cross-functional technical initiatives and influencing engineering direction across teams.
- Ability to reason about complex security systems end to end and communicate technical risk and architectural tradeoffs clearly to different audiences.
- Experience building identity, key-management, network security, or infrastructure security capabilities for cloud platforms is valuable.
- Experience with network policy and encryption or security for high-performance storage and distributed infrastructure is valuable.
- Experience translating security and compliance requirements into automated evidence and production-ready controls is valuable.
- Experience building Kubernetes operators, admission webhooks, or similar infrastructure automation is valuable.
Compensation
The total cash salary range for this position, inclusive of potential bonus value, is $341,400–$401,600. Individual placement is determined by geographic location, experience, skills, and alignment with internal compensation standards. This range is specific to candidates located in the United States. International compensation varies based on local market dynamics. Groq also offers a Long-Term Incentive Program and employee benefits.
Location
Groq prioritizes hiring in or near the San Francisco Bay Area, New York City, and Dallas.
Additional Information
This position may require access to technology or information subject to U.S. export control laws and regulations, including the Export Administration Regulations. Candidates must meet applicable citizenship or residency criteria or otherwise be eligible for an applicable export license. Groq is an equal opportunity employer and provides reasonable accommodations to qualified applicants.