About Us
We are an early-stage technology company operating at the intersection of
Energy and AI infrastructure, focused on developing a new generation of efficient and scalable computing infrastructure.
Our approach combines
distributed computing, modular infrastructure and energy efficiency to support the rapidly growing demand for AI and high-performance computing.
The company is developing a new model for deploying compute capacity in a flexible and scalable way, with a strong focus on
efficiency, sustainability, reliability and responsible infrastructure development.
This is an opportunity to join a growing team at an early stage and contribute directly to the development of a new infrastructure platform, working at the intersection of
power, data centers and advanced computing.
Position Type
Founding member of the Security function, initially reporting to the Head of Software
Role Overview
We are seeking a
Security Engineering Lead to own the security posture and compliance of our self-contained, outdoor-deployable AI/HPC compute systems and the meshed clusters they form. This is a founding security role: you will define the end-to-end security of the product and be hands-on building it, before growing and helping lead the security function as the company scales. The role spans three connected worlds: platform and infrastructure security (a sovereign Kubernetes/Talos GPU cloud), product and system security (physical units deployed in the field), and compliance and governance (a sovereign, multi-tenant offering operating under EU regulation). We do not expect deep mastery of every security domain on day one: we are looking for someone with a holistic security vision and a proven ability to lead through security crises, excellent in at least one core domain and with the appetite and ability to grow into the others.
What You Will Deliver
This is a high-impact, high-ownership role. You will define how our systems protect their tenants, their data, and themselves, and your security architecture will ship across every unit and cluster we deploy.
Within 6 months: You will own and deliver the security architecture of the first compute system prototype: a documented threat model of the system and mesh, hardened Talos/Kubernetes baselines, the identity, secrets and PKI foundations, a tenant-isolation model, and a first detection and incident-response capability validated in the lab. This means driving security technology selection, making key design decisions, and working hands-on to secure the platform and the software supply chain (signed images, SBOM) in our GitOps pipeline.
Within 12 months: You will own the security posture of the first production-ready product: an industrialized, defense-in-depth platform with proven multi-tenant isolation and secure wipe between tenants, and the compliance groundwork laid and ready for our first certification. Working closely with network, software, and hardware colleagues, you will deliver a security architecture that is documented, automated, auditable, and ready to scale into series deployment, and you will begin setting the standards and practices for a growing security team.
Key Responsibilities
- Own the end-to-end security posture and threat model of the system and meshed cluster, across product/system, platform, identity, data, and inter-site security
- Define and implement defense-in-depth for the Kubernetes/Talos platform: node and cluster hardening (CIS benchmarks), admission control (OPA/Kyverno), runtime security (e.g. Falco), and NetworkPolicies
- Own identity, secrets, and PKI: OIDC single sign-on and RBAC, secrets management (e.g. Vault), an internal PKI, and key/certificate lifecycle (HSM where required)
- Guarantee multi-tenant isolation: workload isolation across VMs and containers (KubeVirt, MIG), encryption, secure wipe between tenants, and attestation
- Stand up detection and incident response: security logging and SIEM, alerting, playbooks, and lead security crisis management end to end
- Secure the software supply chain: SBOM, image signing (cosign/sigstore), dependency and infrastructure-as-code scanning, and secure GitOps practices
- Own security compliance and governance: drive the information security management system and the sovereignty roadmap (ISO/IEC 27001, SecNumCloud, NIS2/GDPR and EU-cloud alignment), including policies, risk management, and audit readiness
- Contribute to product and system security together with the hardware team: secure boot, TPM/measured boot and attestation, supply-chain integrity, and hardening of deployed units
- Collaborate closely with network (segmentation, zero-trust, mesh), software, and hardware colleagues, and produce security architecture documents, threat models, and operational runbooks
- Set security standards and practices as the function grows, with a path to build and help lead a small security team
Requirements
- Bachelor’s degree in Computer Science, Engineering, Cybersecurity, or equivalent field
- 7-12 years of hands-on security experience in cloud/infrastructure, platform, or product security, including time in a lead or leadership role
- A proven holistic security vision and a demonstrated ability to lead and manage security incidents and crises end to end
- Hands-on experience contributing to the implementation of at least one recognized framework, ISO/IEC 27001, SecNumCloud (ANSSI), or NIS2/GDPR and EU-cloud regulation, with a solid command of its requirements
- Deep expertise in at least one of: (a) cloud-native/Kubernetes platform hardening, (b) identity, secrets and PKI, or (c) multi-tenant workload isolation, with the appetite and ability to grow into the others
- Strong foundations in detection and response and in software supply-chain security
- Ability to work in a fast-paced, early-stage environment with a high degree of ownership and autonomy
- English speaking
Nice to Have
- Experience securing sovereign, multi-tenant, or otherwise regulated cloud/infrastructure
- Product or system security and hardware-integration security: secure boot, TPM/measured boot and attestation, and confidential computing
- Hands-on with cloud-native security tooling (e.g. Falco/Tetragon, OPA/Kyverno, Vault, cosign/sigstore, Trivy)
- Familiarity with the target stack (Talos Linux, Cilium, KubeVirt, Ceph, GitOps/FluxCD)
- Familiarity with zero-trust networking and network segmentation for multi-tenant infrastructure
- Prior experience at a hardware or infrastructure startup or scale-up, where scope and pace require broad ownership
Location
Milan, Italy.