Security Engineer, Application
Firmus
Sydney, Australia · Onsite · Full Time
Posted
Job description
Firmus Technologies Firmus Technologies is a global leader pioneering the development and operation of efficient AI infrastructure across Asia Pacific. Founded in Australia in 2019, our mission is to create the most efficient AI infrastructure by combining cutting-edge technology with a steadfast commitment to sustainability. At Firmus, we are unique in our approach. We design, build, and operate a new class of digital infrastructure – the AI Factory. Through our model-to-grid technology approach, we have pushed the boundaries of multi-generational liquid cooling systems, energy management, AI software orchestration, and construction. For our customers, this approach allows us to make every watt count and deliver low-cost AI tokens globally. Firmus AI Cloud Our large-scale GPU cloud platform, Firmus AI Cloud, is purpose-built to deliver energy-efficient AI compute at scale to customers. It empowers developers, enterprises, educational institutions, and government users to train and deploy AI models with unmatched efficiency and cost savings. With an ever-growing suite of services and applications, we are committed to delivering a cloud experience that is market-leading, proprietary, and built to scale. ROLE SUMMARY Firmus Technologies is seeking a Senior Security Engineer, Application for our Engineering and Technology team. You own application security for Firmus AI Cloud and the internal software that runs it. Automation is how you scale that ownership. Customers provision GPU compute through API and console, software engineers build against it, and our operators run the platform through the same control plane. You own the security of that software: the public APIs, the services behind them, how tenants stay separated inside the application, and the AI assistants and agents we ship on top. KEY RESPONSIBILITIES Automation and secure delivery Own the CI/CD security gates that every production repository passes through: SAST, DAST, SCA, secrets detection, and SBOM generation. Build the systems that do the repeatable work: finding triage, dependency uplift, evidence collection, and draft threat models. Ship the secure paved roads other teams build on: reusable libraries, service templates, and developer tooling. Write and review code in the services you protect, including the security-critical paths that tools miss. Security architecture and standards Set the…