Organizational Leadership: Lead, mentor, and empower a team of 5–6 infrastructure security engineers. Optimize delivery processes and elevate the team into a high-throughput engineering organization
Engineering Rigor & Velocity: Transition the team to a proactive platform engineering model with clear shipping cadences, code quality standards, and architectural roadmaps
Strategic Growth & Hiring: Establish clear accountability and strategically hire additional engineering talent to complement existing strengths in systems security and automation
Identity, Secrets & PKI: Build, operate, and scale core identity and crypto primitives, including workload identity (SPIFFE/SPIRE), enterprise secrets-as-a-service (HashiCorp Vault), and public key infrastructure (PKI) across multi-tenant GPU environments
Fleet Telemetry & eBPF: Deploy and manage eBPF-based security sensors at scale across bare-metal and virtualized fleets to deliver high-fidelity observability and kernel-level runtime protection
Fleet Access & Just-In-Time (JIT): Architect and enforce zero-trust, JIT access mechanisms for engineers and operators accessing fleet nodes, hypervisors, and core switches
Firmware & Supply Chain Security: Build mechanisms for secure boot, hardware roots of trust, firmware update delivery, and software supply chain verification across GPU nodes, CPUs, and network fabrics
Infrastructure Vulnerability Management: Build platforms to continuously track, prioritize, and remediate vulnerability states across millions of bare-metal, containerized, and hypervisor assets
Control Plane & Cloud Security: Secure Crusoe’s multi-layer control plane across public cloud environments (GCP) and multi-gigawatt on-premise AI data center infrastructure
IAM & Elimination of Standing Secrets: Eliminate standing admin privileges and long-lived secrets. Architect least-privilege RBAC/ABAC models across cloud projects and physical infrastructure
Architectural Isolation & Risk Reduction: Identify and eliminate systemic architectural risks (e.g., decoupling co-mingled Terraform execution environments, isolating tenant control planes, and establishing hard boundary enforcement across GCP projects and GPU clusters)
Security Architecture & Governance-by-Code: Perform continuous security architecture reviews, enforcing change management, isolation, and baseline posture natively through IaC (Terraform, OpenTofu, Kubernetes operators)