Senior Platform Engineer Security positions focus on delivering results in their domain. This page aggregates open Senior Platform Engineer Security roles and what employers typically expect.
About RUM Group Inc. RUM Group Inc. is an AI infrastructure and video company. Its Quake AI business delivers AI compute as a service, operating AI data centers including GPU and CPU compute, storage, and networking at scale. Rumble, RUM Group's video business and the original tenant of Quake AI, provides creators and enterprises a full suite of video technologies, unlocking reach, scale, and monetization. RUM Group is building the rails of the agentic-first enterprise: the AI compute, cloud infrastructure, and trust layer for the agentic AI future, advancing RUM Group's mission to maximize the power of human imagination. For more information visit www.rum.group . Rumble Cloud is seeking a Senior Platform Engineer (Security) to help operate, secure, and continuously harden the infrastructure that powers our public cloud, built on OpenStack and Ceph. This role sits at the intersection of platform engineering and security operations: you’ll apply and maintain security hardening across our Linux fleet and cloud control plane, track vulnerabilities through to remediation, and serve as a key engineering partner for internal and external audits. Strong Linux fundamentals are essential, and demonstrated security expertise, ideally backed by certification, is a significant differentiator. You’ll work across operating systems, OpenStack and Ceph components, and Kubernetes, using automation to keep baselines consistent and auditable. You’ll partner closely with cloud engineering, DevSecOps, and compliance stakeholders to ensure the platform meets both reliability and security expectations as it grows. If you enjoy hardening Linux at scale, working directly with vulnerability and control frameworks such as CIS Benchmarks and ISO 27001, and contributing to the security posture of mission-critical cloud infrastructure, this role offers substantial impact and technical depth. Responsibilities Assess, implement, and maintain security hardening (CIS Benchmarks, STIGs, or equivalent) across Linux hosts, hypervisors, and the cloud control plane, using automated baselines with tools such as Ansible and Terraform. Track and remediate vulnerabilities at the infrastructure layer, including operating systems and platform components such as OpenStack, Ceph, and Kubernetes, maintaining accurate inventory, patch SLAs, and risk-based prioritization. Coordinate with the DevSecOps Engineer on application- and pipeline-layer remediation, ensuring alignment between platform hardening and SSDLC practices. Serve as a primary technical contributor to internal and external audits, including evidence collection, control narratives, and responses to auditor questions, mapping work to ISO 27001 and other relevant frameworks. Operate and improve core platform services on Linux infrastructure, contributing to automation, capacity planning, incident response, and reliability engineering. Help design logging, monitoring, and alerting that support both operational and security use cases, in collaboration with platform, security, and SRE teams. Document hardening baselines, security controls, and operational procedures clearly so that they are repeatable, testable, and auditable. Qualifications Strong Linux systems engineering background (systemd, networking, storage, package management) on major Linux distributions. Hands-on experience applying security hardening standards such as CIS Benchmarks, STIGs, or equivalent at production scale. Solid understanding of vulnerability management (CVSS scoring, risk-based prioritization) and Linux security controls (SELinux or AppArmor, auditd, PAM, host firewalling). Experience with infrastructure automation using Ansible, Terraform, and scripting in Bash and/or Python. Experience supporting compliance or audit activities, including evidence collection, control documentation, and working directly with auditors or security teams. Strong understanding of identity and authentication concepts (SSO, OAuth2/OIDC, privileged access) an…