About the Role
As Bitdeer AI Cloud's first dedicated hands-on security leader for the Americas, you will own the full-stack security and 7x24 security operations of AI Data Centers (AIDCs) across California, Tennessee, and Washington. This is a deeply hands-on technical operations role, personally leading detection engineering, incident response, and host/network hardening, while also handling US customer incident response and cross-time-zone coordination with Singapore HQ. The core mission is to ensure secure GPU compute business operations across three Americas AIDCs while driving incident MTTR to industry-leading levels, despite significant time differences with HQ.
Responsibilities
- Serve as the primary on-call security lead for the Americas region, owning 7x24 alert triage, incident response, and root cause analysis.
- Act as the primary security decision-maker for the Americas during PST business hours when Singapore HQ is offline.
- Personally drive the response to high-severity incidents including cryptojacking, ransomware, data exfiltration, and tenant escape scenarios.
- Lead the full forensics, containment, and recovery cycle for security incidents.
- Build and maintain Americas regional incident response playbooks and runbooks.
- Collaborate with the global SecOps team on SIEM detection rules, SOAR automation, and IR tabletop exercises.
- Lead customer security incident response, engaging customer security teams and coordinating with Sales and Customer Success.
- Serve as the Americas escalation interface, coordinating decisions with Singapore HQ, Legal, and business teams during major incidents.
- Personally write SIEM detection rules covering typical GPU cloud attack scenarios.
- Design detection coverage assessments based on the MITRE ATT&CK Cloud Matrix and Container Matrix.
- Proactively identify and close visibility blind spots in detection coverage.
- Lead hypothesis-driven threat hunting activities, producing comprehensive hunting reports and new detection rules.
- Design runtime detection capabilities using eBPF tools to complement traditional HIDS detection.
- Operationalize detection-as-code practices in the Americas region.
- Lead pre-production security readiness assessments for all Americas AIDCs.
- Personally drive host hardening initiatives.
- Partner with the Platform Engineering team to deploy eBPF-based runtime security monitoring.
- Track CVEs for critical components and lead Americas regional vulnerability response.
- Lead Americas regional IAM and privileged access management.
- Lead the configuration and operations of perimeter firewalls, IPS, and WAF for all Americas AIDCs.
- Engage DDoS scrubbing services and build robust Americas regional DDoS response plans.
- Establish east-west traffic baselines to identify anomalous traffic patterns.
- Configure BGP RPKI, source address validation, and other network-layer security controls.
- Plan and deploy traffic analysis solutions to enable full traffic traceability at physical boundaries.
- Respond to customer-submitted security tickets, abuse complaints, and incident notifications.
- Handle US law enforcement requests, collaborating closely with Legal.
- Establish Americas regional customer security incident SLA tracking and post-incident review mechanisms.
- Establish seamless security collaboration mechanisms between the Americas and Singapore HQ.
- Serve as the Americas regional compliance support interface, partnering with the Singapore GRC Manager.
- Represent Bitdeer AI Cloud Security within local US security communities and industry events.
Requirements
- Bachelor's degree or higher in Computer Science, Cybersecurity, Computer Engineering, or a related technical field.
- 10+ years of hands-on information security experience, with at least 5 years strictly focused on cloud infrastructure / IaaS / data center security technical operations.
- Deep incident response experience as an Incident Commander, having successfully led at least 5 P0/P1 security incidents end-to-end.
- Thoroughly familiar with the NIST SP 800-61 IR process.
- Deep expertise in Linux system security, network protocols, TCP/IP, virtualization (KVM/QEMU), and container/Kubernetes security.
- Hands-on experience with at least one mainstream SIEM platform (Wazuh / Splunk / Elastic SIEM / Sentinel) and the ability to independently write detection rules.
- Familiarity with the SIGMA rule format is required.
- Familiar with the MITRE ATT&CK Framework (Cloud Matrix and Container Matrix) with a proven ability to design detection coverage assessments.
- Strong scripting and programming skills: Python (Required) + Shell (Required); Go or Rust are highly preferred.
- Ability to independently develop security tools and automation scripts.
- Familiarity with the eBPF technology stack (Tetragon / Falco / Cilium) and a strong understanding of its application in cloud-native runtime security.
- Familiarity with at least one IaC tool (Terraform / Ansible) and standard Git workflows to codify security configurations.
- At least one of the following industry certifications is required: GCIH, GCIA, GCFA, OSCP, CISSP, CCSP.
- Professional fluency in both English and Mandarin Chinese is required.
- Willingness to accept irregular working hours.
- Must participate in a 7x24 on-call rotation during major incidents and conduct daily cross-time-zone coordination with Singapore HQ (SGT).
Skills
- Detection Engineering
- Incident Response
- Host Hardening
- Network Hardening
- SIEM (Wazuh, Splunk, Elastic SIEM, Sentinel)
- SOAR
- Forensics
- Containment
- Recovery
- Playbook Development
- Runbook Development
- Threat Hunting
- eBPF (Tetragon, Falco, Cilium)
- Linux Security
- Network Protocols
- TCP/IP
- Virtualization (KVM/QEMU)
- Container Security
- Kubernetes Security
- InfiniBand Security
- NVIDIA GPU Driver Security
- CUDA Security
- NCCL Security
- UFM Security
- BMC/IPMI Hardening
- IAM
- Privileged Access Management
- Firewall Configuration
- IPS Configuration
- WAF Configuration
- DDoS Mitigation
- NetFlow/IPFIX Analysis
- BGP RPKI
- Source Address Validation (uRPF)
- Traffic Analysis
- Python Scripting
- Shell Scripting
- Go Programming
- Rust Programming
- Infrastructure as Code (Terraform, Ansible)
- Git Workflows
- Compliance Support
- GRC
Location
- California
- Tennessee
- Washington
Work Type
- 7x24 Operations
- On-call Rotation
Experience Level
- 10+ years of information security experience
- 5+ years focused on cloud infrastructure / IaaS / data center security technical operations
Education Level
- Bachelor's degree or higher in Computer Science, Cybersecurity, Computer Engineering, or a related technical field
About the Company
- Bitdeer is a world-leading technology company for AI and Bitcoin mining infrastructure.
- Bitdeer is committed to providing comprehensive Bitcoin mining solutions for its customers and building AI computational infrastructure to support the AI revolution.
- Bitdeer handles complex processes involved in computing such as equipment procurement, transport logistics, data center design and construction, equipment management, and daily operations.
- Bitdeer also offers advanced cloud capabilities to customers with high demand for artificial intelligence.
- Headquartered in Singapore, Bitdeer has deployed data centers across multiple countries, including the United States, Norway, Bhutan, and Ethiopia.
Equal Opportunity
- Bitdeer is committed to providing equal employment opportunities in accordance with country, state, and local laws.
- Bitdeer does not discriminate against employees or applicants based on conditions such as race, color, gender identity and/or expression, sexual orientation, marital and/or parental status, religion, political opinion, nationality, ethnic background or social origin, social status, disability, age, indigenous status, and union.
