高级应用安全工程师
Senior Application Security Engineer
作为vCluster Labs的高级应用安全工程师,你是我们多样化生态系统中信任的架构师。在这个职位上,你将负责我们产品的端到端安全,确保vCluster仍然是安全Kubernetes多租户的行业标准。你将制定安全标准,使客户能够放心运行高权限工作负载,构建覆盖我们整个代码库和基础设施的深入策略。
作为高级应用安全工程师,你的职责包括:
- 核心产品安全:对我们的基于Go的核心应用程序和Kubernetes控制器以及前端用户界面进行深入的安全审查。重点关注避免在多租户架构中出现权限提升。
- 威胁建模:主导新功能的威胁建模流程,主动识别与共享GPU资源和多云环境相关的风险。
- 自动化安全:通过持续将安全检查集成到我们的CI和开发人员工作流中来实现“左移”。优化这些检查以提高速度,确保安全永远不会成为工程效率的瓶颈。此外,你还将管理我们整个产品栈的自动化和手动扫描。
- 漏洞管理:负责安全漏洞的全生命周期,从发现到修复。你将处理外部和内部报告,推动跨工程团队解决关键问题,并在各利益相关方之间有效沟通。
- 功能开发:组织中的每个人都参与新功能的想法和开发。其中许多功能直接与安全主题相关,如容器逃逸和隔离,在受限环境中推动可能的边界。
- 开发者培训:让所有工程师更容易理解复杂主题,包括新的攻击向量和安全编码概念。
如果你具备以下条件,这个职位可能适合你:
- 经验:你在应用安全或产品安全领域有5年以上经验,重点在容器化环境。
- Kubernetes深度:你对Kubernetes架构、RBAC和容器运行时安全有深入了解。你了解多租户的具体风险。
- 代码能力:你熟悉阅读和编写Go语言,这是我们核心产品的语言。你可以在PR中识别漏洞,而无需过多依赖工具。
查看英文原文
As a Sr. Application Security Engineer at vCluster Labs, you are the architect of trust in our diverse ecosystem. In this role, you will be responsible for the end-to-end security of our product, ensuring that vCluster remains the de facto standard for secure Kubernetes multi-tenancy. You will define the security standards that allow our customers to run high-privileged workloads without fear, building in-depth strategies that span our entire codebase and infrastructure.
As a Sr. Application Security Engineer, your role will include:
- Core Product Security: Perform deep-dive security reviews of our core Go-based applications and Kubernetes controllers, as well as the frontend user interface. With a targeted focus on avoiding privilege escalation within our multi-tenant architecture.
- Threat Modeling: Lead the threat modeling process for new features, proactively identifying risks associated with shared GPU resources and multi-cloud environments.
- Automated Security: "Shift left" by continuing to integrate security checks into our CI and developer workflows. Optimizing these checks for speed, ensuring security never becomes a bottleneck for engineering velocity. Separately, you will manage automated and manual scanning of our entire product stack.
- Vulnerability Management: Own the lifecycle of security vulnerabilities from discovery to remediation. You will triage both external and internal reports, drive the resolution of critical issues across the engineering organization, and communicate effectively across stakeholders.
- Feature Development: Everyone at the organization contributes to both the ideas and development of new features. Many of which are directly related to security topics such as container breakouts and isolation, pushing the envelope of what’s possible in constrained environments.
- Developer training: Make complex topics easier to understand for all engineers, including new attack vectors and secure coding concepts.
This role could be a fit for you if you bring:
- Experience: You have 5+ years in Application Security or Product Security, with a strong focus on containerized environments.
- Kubernetes Depth: You have a deep understanding of Kubernetes architecture, RBAC, and container runtime security. You understand the specific risks of multi-tenancy.
- Code Proficiency: You are comfortable reading and writing Go, which is the language of our core product. You can spot a vulnerability in a PR without relying solely on automated tools.
- Modern Tech Mindset: You thrive in fast-paced cutting-edge environments. You are excited to solve novel problems related to AI and multi-tenant infrastructure.
- Cognitive Flexibility: You view feedback as a learning mechanism, not a critique, and are willing to understand the unique needs and concerns of our customers.
Bonus points for:
- Certifications: CKS (Certified Kubernetes Security Specialist) or OSCP.
- AI/GPU Context: Experience securing AI workloads or GPU cloud infrastructure.
- Automation Skills: Experience writing custom security tooling or automation scripts in Python or Go.
- Documentation: A willingness to contribute to our public-facing security documentation and "Trust Center" to help our customers navigate compliance.
ABOUT VCLUSTER LABS
We're the #1 platform for AI infrastructure, trusted by the world's fastest-growing AI cloud builders. We're a venture-backed startup that's raised over $28M from top-tier investors including Khosla Ventures (first investor in OpenAI, GitLab, Stripe, and DoorDash), and we're in a hyper-growth phase looking for motivated people to join our team. Our headquarters are in San Francisco (Salesforce Tower), but our team is distributed around the globe with a remote-first culture.
We give AI Cloud providers and AI factories a hyperscaler-like experience on their own GPU infrastructure. Our platform runs the full stack an operator needs, from bare metal provisioning and node lifecycle management up through managed Kubernetes, Slurm, Ray, and inference clusters, so they can turn raw GPUs into cluster products they can sell in days instead of spending 12+ months building it themselves. Today we power over 100,000 GPUs and 1 million CPUs across 50+ AI clouds and Fortune 500 companies, backed by a team of 40+ infrastructure engineers who build alongside our customers rather than just shipping them software.
We're the company behind vCluster, the open source technology for tenant isolation on Kubernetes, with 11,000+ GitHub stars and 40M+ tenant clusters created since 2021. Open source is part of our DNA. At KubeCon North America 2025, we launched our Infrastructure Tenancy Platform for AI, a Kubernetes-native framework built for running AI, ML, and GPU-intensive workloads anywhere, with an NVIDIA-validated reference architecture for DGX systems.
Benefits
We offer the following benefits:
- Competitive Salary: We offer a competitive compensation package, including equity.
- Platinum-Level Insurance: Health, dental, vision, and life Insurance, including plans for you and eligible dependents (benefits vary depending on country).
- Flexible Working Schedule: You have a doctor’s appointment or need to head to the supermarket to get groceries at 2pm? We won’t have an issue with that. To us, results matter more than clocking in and out at the same time every day.
- Workplace Flexibility: We’re very flexible about where you work. We know things can change in life and we’re happy to adjust the work environment for you along the way.
CULTURE & VALUES
At vCluster Labs, we value and stand for:
1. Make it Happen: We have a relentless bias for action and the grit to push through obstacles. We do whatever it takes to figure it out, put in the work, and ruthlessly prioritize the actions that drive measurable impact for the business.
2. Own the Outcome: We understand that our responsibility doesn't end when a task is checked off; it ends when the value is delivered. We connect our daily individual actions to the broader success of the company and our customers.
3. Create Wow: We measure success by the experience we generate, both inside and outside the company. For our customers, this means impressive speed and intuitive experiences. For our team, this means going the extra mile to support one another and to continuously drive each other to new heights.
4. Open Source, Open Mind: We are actively contributing to and maintaining open-source projects. Internally, we foster meritocracy — the strongest ideas win, no matter who or where they come from.
5. Build Tomorrow’s Standards, Intentionally: We don't just ship software; we define the state-of-the-art of tomorrow. We are fearless in tearing down old approaches to build something better, but we are disciplined in how we do it because we know our users rely on our technology to run mission-critical infrastructure platforms.