Principal Platform Identity Engineer at Firmus Technologies | AU | Rezi

Principal Platform Identity Engineer at Firmus Technologies

Principal Platform Identity Engineer

Firmus Technologies · AU

2 days ago

Principal Platform Identity Engineer

Firmus Technologies · AU

2 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Principal Platform Identity Engineer role.

Rezi rewrites your resume against Firmus Technologies's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Principal Platform Identity Engineer posting at Firmus Technologies — free, in seconds.

About the Role

AI FactoryOS Operations runs Firmus' proprietary operating system for the AI Factory in production, ensuring 24/7 reliability and service levels for AI FactoryOS, Firmus AI Cloud, and associated platforms. This engineering function develops automated remediation and operational tooling, transforming manual responses into software-defined capabilities and managing shared services essential for the estate's operation. They collaborate closely with platform engineering teams, providing production insights to guide future development and fixes.

Responsibilities

  • Design, build, and operate the workforce and service identity platform, including single sign-on and identity provider integration.
  • Design, build, and operate the internal certificate authority and certificate lifecycle management for the estate.
  • Design and operate the secrets management platform, including rotation, access policy, and audit.
  • Automate identity, certificate, and secrets provisioning as code, embedded into CI/CD and infrastructure-as-code workflows.
  • Own the privileged access management model, including just-in-time elevation tied to a change record, approval workflows, and recorded break-glass access.
  • Implement and enforce least-privilege access patterns across the estate.
  • Report on whether access matches the model in practice.
  • Design the trust plane for resilience, including certificate and secret rotation.
  • Design and operate key custody for the estate's cryptographic material under dual control.
  • Own the delegated-authority model for custody and out-of-hours cover.
  • Harden the identity, certificate, and secrets services.
  • Produce access and certificate evidence for ISO 27001, SOC 2, and enterprise customer due diligence.
  • Provide deep technical expertise for identity, certificate, and secrets faults.
  • Approve and review just-in-time access requests requiring judgment beyond the standard workflow.
  • Mentor engineers on identity and secret management practices.
  • Ensure no one approves their own access and privileged access to the trust plane is approved outside the team.

Requirements

  • Deep experience designing, building, and operating identity and access management platforms.
  • Strong experience with certificate lifecycle management and internal public key infrastructure.
  • Strong experience with secrets management platforms, including rotation, access policy, and audit.
  • Practical experience with privileged access management, just-in-time elevation, and break-glass design for production environments.
  • Experience with hardware security modules and key custody practices for production cryptographic material.
  • Solid understanding of zero-trust architecture principles and their application to multi-tenant platforms.
  • Experience embedding identity and secrets into CI/CD and infrastructure-as-code workflows.
  • Strong scripting or programming ability for identity automation and tooling (e.g., Python, Go, Bash).
  • Demonstrated experience as a senior escalation point for identity and security-adjacent faults in a 24/7 production environment.
  • Practical understanding of how identity and access controls produce evidence for frameworks like ISO 27001 or SOC 2.
  • Clear technical judgment and communication skills.
  • Experience with Kubernetes-native identity patterns (preferred).
  • Experience in a multi-tenant service provider, cloud, or colocation environment (preferred).
  • Familiarity with GPU or HPC infrastructure and its identity and access requirements (preferred).
  • Relevant security or identity certification (preferred).
  • A Bachelor's degree in computer science, engineering, or a related discipline, or an equivalent combination of relevant experience and training (preferred).

Skills

  • Identity and Access Management (IAM)
  • Single Sign-On (SSO)
  • Identity Provider Integration (Okta, Keycloak, Entra ID, authentik)
  • Certificate Lifecycle Management
  • Internal Public Key Infrastructure (PKI)
  • step-ca
  • Secrets Management (HashiCorp Vault, OpenBao)
  • Privileged Access Management (PAM)
  • Just-in-Time (JIT) Elevation
  • Break-Glass Procedures
  • Hardware Security Modules (HSMs)
  • Key Custody
  • Zero Trust Architecture
  • CI/CD
  • Infrastructure-as-Code (IaC)
  • Python
  • Go
  • Bash
  • ISO 27001
  • SOC 2
  • Kubernetes-native identity patterns (preferred)
  • SPIFFE/SPIRE (preferred)
  • GPU/HPC infrastructure (preferred)

Location

  • Australia
  • Singapore

Work Type

  • On-call
  • 24/7 escalation roster

Experience Level

  • Principal
  • Senior

Education Level

  • Bachelor's degree in computer science, engineering or a related discipline, or an equivalent combination of relevant experience and training

About the Company

  • Firmus runs large-scale, state-of-the-art AI infrastructure built on the latest generation of GPU rack-scale systems and operated as one estate to power the next generation of AI innovation.
  • AI FactoryOS is Firmus' proprietary operating system for the AI Factory, governing GPU telemetry, cooling, power, and grid interaction as an integrated layer for site optimization and monitoring.