Senior Security Architect

NVIDIA NVIDIA · Semiconductors · Santa Clara, CA +1 · Remote

Senior Security Architect role at NVIDIA focused on securing at-scale infrastructure, high-performance computing environments, and AI cluster systems. Responsibilities include designing, implementing, and evolving security systems, policies, and operational practices to protect critical infrastructure and intellectual property. The role involves identifying and assessing cybersecurity risks, developing incident response and disaster recovery plans, and ensuring systems meet various standards. Experience securing large-scale Linux infrastructure, risk management, incident response, and securing AI agents using sandboxing and AI-based threat detection are required.

What you'd actually do

  1. Build and enforce security controls, systems, and policies for cluster infrastructure of new NVIDIA hardware.
  2. Identify, assess, and reduce cybersecurity risks; report major risks clearly to leadership.
  3. Develop and lead incident response and disaster recovery plans.
  4. Investigate security incidents and drive root-cause analysis.
  5. Ensure systems meet IT, legal, regulatory, and information security standards.

Skills

Required

  • Experience securing large-scale Linux infrastructure
  • Proven understanding of risk management, threat modeling, vulnerability management, and access control
  • Experience with incident response, disaster recovery, and breach handling
  • Knowledge of compliance, governance, and data protection requirements
  • Clear written and verbal communication with technical and leadership audiences
  • Experience in programming secure computing environments, with proficiency in C/C++
  • BS in Computer Science, Engineering, Cybersecurity, or equivalent experience with 8+ yrs of industry experience
  • Experience with system level threat modeling, risk management frameworks and risk mitigation techniques
  • Experience with compute and networking systems security architecture and engineering
  • Experience in securing AI agents using sandboxing technologies and AI-based threat detection (e.g. Mythos)

Nice to have

  • Experience with modern authentication and identity frameworks such as OAuth 2.1, OIDC, Kerberos, FIDO2/WebAuthn
  • Experience with Microsoft Active Directory and Entra ID, including cross-realm trusts and identity federation (SCIMv2)
  • Experience managing centralized Linux identity (FreeIPA/RHEL IdM/SSSD), including PKI lifecycle management and Host-Based Access Control
  • Linux kernel hardening (SELinux/AppArmor) and observability (eBPF)
  • Developing secure software in Rust, prioritizing memory safety
  • Experience hardening HPC schedulers and storage, Slurm alongside parallel filesystems like Lustre and NFS
  • Experience securing containerized workloads (Docker, Enroot, Kubernetes)
  • Knowledge of high-speed fabric security like InfiniBand PKeys/MKeys
  • Zero Trust, ZTNA, VRFs, VLANs, performance-optimized firewalls
  • Use of advanced vulnerability management and supply chain mitigation (CVSS 4.0, SBOM)

What the JD emphasized

  • Experience in securing AI agents using sandboxing technologies and AI-based threat detection (e.g. Mythos)