All jobs

Principal Platform Identity Engineer

Firmus

Sydney, Australia, Australia · Australia
Salary undisclosed
full_time
onsite
English

Posted 6h ago · Sep 22, 2026

Job description

<p><strong><span data-contrast="none"><span data-ccp-parastyle="Body Text">AI FactoryOS Operations</span></span></strong><span data-ccp-props="{"201341983":0,"335559738":145,"335559740":264}">&nbsp;</span></p> <p><span data-contrast="auto"><span data-ccp-charstyle="normaltextrun" data-ccp-charstyle-defn="{"ObjectId":"ac0262f4-8a9e-5820-b908-2d943c5f7113|1","ClassId":1073872969,"Properties":[201342446,"1",201342447,"5",201342448,"1",201342449,"1",469777841,"Calibri",469777842,"Arial",469777843,"Calibri",469777844,"Calibri",201341986,"1",469769226,"Calibri,Arial",268442635,"22",469775450,"normaltextrun",201340122,"1",134233614,"true",469778129,"normaltextrun",335572020,"1",469778324,"Default Paragraph Font"]}">AI FactoryOS is Firmus' proprietary operating system for the AI Factory. It governs GPU telemetry, cooling, power and grid interaction as one integrated layer, so that every Firmus site can be optimised and monitored as a single system.</span></span><span data-ccp-props="{"134233117":true,"134233118":true,"134245417":true}">&nbsp;</span></p> <p><span data-contrast="auto">AI FactoryOS Operations runs that platform in production and owns the 24/7 reliability of AI FactoryOS, Firmus AI Cloud and the platforms built on them, together with the service levels the estate is measured against.</span><span data-ccp-props="{"335559738":240,"335559739":240}">&nbsp;</span></p> <p><span data-contrast="auto">The remit is an engineering one. The function builds the guarded automation, remediation and operational tooling that turn manual response into a software-defined capability, and builds and operates the shared services the estate's own operation depends on. The function works closely with the engineering teams that build the platform, supplying the production evidence that shapes what they fix and what they build next.</span><span data-ccp-props="{"335559738":240,"335559739":240}">&nbsp;</span></p> <p><span data-ccp-props="{"134233117":false,"134233118":false,"134245417":true,"335559738":0,"335559739":0}">&nbsp;</span></p> <p><strong><span data-contrast="none"><span data-ccp-parastyle="Body Text">Principal Platform Identity Engineer</span></span></strong>&nbsp;<br><span data-contrast="none"><span data-ccp-parastyle="Body Text">Role Summary</span></span><span data-ccp-props="{"201341983":0,"335559738":145,"335559740":264}">&nbsp;</span></p> <p><span data-contrast="auto"><span data-ccp-charstyle="normaltextrun">Firmus runs large-scale, state-of-the-art AI infrastructure built on the latest generation of GPU rack-scale systems and operated as one estate to power the next generation of AI innovation. </span><span data-ccp-parastyle="paragraph">The Principal Platform Identity Engineer </span><span data-ccp-parastyle="paragraph">builds and operates</span><span data-ccp-parastyle="paragraph"> the </span><span data-ccp-parastyle="paragraph">trust plane the estate's administrative and privileged access</span><span data-ccp-parastyle="paragraph"> depends on: workforce and </span><span data-ccp-parastyle="paragraph">privileged</span><span data-ccp-parastyle="paragraph"> identity, the internal certificate authority, secrets management, and the just-in-time access model tied to the change record. </span><span data-ccp-charstyle="normaltextrun">This is the trust plane of the platform, the foundation that access, privilege and every service's authentication rest on.</span></span><span data-ccp-props="{"134233117":true,"134233118":true,"134245417":true,"335557856":16777215}">&nbsp;</span></p> <p><span data-contrast="auto"><span data-ccp-charstyle="normaltextrun">This is a hands-on principal-level role with deep technical expertise. The trust plane is engineered, not administered: identity, certificates and secrets are provisioned as code, integrated into the delivery pipeline, and designed for rotation and recovery from the outset. The role holds key custody for the estate and carries out-of-hours accountability for the trust plane alongside a peer.</span></span><span data-ccp-props="{"134233117":false,"134233118":false,"134245417":true,"335557856":16777215,"335559738":0,"335559739":0}">&nbsp;</span></p> <p><strong><span data-contrast="none"><span data-ccp-parastyle="Body Text">Key Responsibilities</span></span></strong><span data-ccp-props="{"201341983":0,"335559738":145,"335559740":264}">&nbsp;</span></p> <ul> <li data-leveltext="" data-font="Symbol" data-listid="49" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="none"><span data-ccp-parastyle="FIR Body List" data-ccp-parastyle-defn="{"ObjectId":"15ef5dd6-cc84-5693-b085-6dad75ec09b1|1","ClassId":1073872969,"Properties":[469777841,"Aeonik",469777842,"Aeonik",469777843,"Aeonik",469777844,"Aeonik",469769226,"Aeonik",201342446,"1",201342447,"5",201342448,"1",201342449,"1",201341986,"1",268442635,"20",335551500,"197122",335559740,"264",201341983,"0",335559738,"145",469775450,"FIR Body List",201340122,"2",134234082,"true",134233614,"true",469778129,"FIRBodyList",335572020,"1",469778324,"Body Text"]}">Design, build and operate the workforce and service identity platform, including single sign-on and identity provider integration (for example authentik, Okta, Keycloak or Entra ID).</span></span><span data-ccp-props="{"201341983":0,"335559738":145,"335559740":264}">&nbsp;</span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="49" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="none"><span data-ccp-parastyle="FIR Body List">Design, build and operate the internal certificate authority and certificate lifecycle management for the estate (for example step-ca or an equivalent internal PKI), and the secrets management platform (for example OpenBao or HashiCorp Vault), including rotation, access policy and audit.</span></span><span data-ccp-props="{"201341983":0,"335559738":145,"335559740":264}">&nbsp;</span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="49" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="none"><span data-ccp-parastyle="FIR Body List">Automate identity, certificate and secrets provisioning as code, embedded into CI/CD and infrastructure-as-code workflows, so that access and credentials are never provisioned by hand.</span></span><span data-ccp-props="{"201341983":0,"335559738":145,"335559740":264}">&nbsp;</span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="49" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="4" data-aria-level="1"><span data-contrast="none"><span data-ccp-parastyle="FIR Body List">Own the privileged access management model: just-in-time elevation tied to a change record, approval workflows, and recorded break-glass access for emergencies.</span></span><span data-ccp-props="{"201341983":0,"335559738":145,"335559740":264}">&nbsp;</span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="49" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="5" data-aria-level="1"><span data-contrast="none"><span data-ccp-parastyle="FIR Body List">Implement and enforce least-privilege access patterns across the estate to the policy set by the Platform Security Engineers, and report on whether access matches the model in practice, with independent audit of that access carried out by Security.</span></span><span data-ccp-props="{"201341983":0,"335559738":145,"335559740":264}">&nbsp;</span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="49" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="6" data-aria-level="1"><span data-contrast="none"><span data-ccp-parastyle="FIR Body List">Design the trust plane for resilience, including certificate and secret rotation.</span></span><span data-ccp-props="{"201341983":0,"335559738":145,"335559740":264}">&nbsp;</span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="49" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="7" data-aria-level="1"><span data-contrast="none"><span data-ccp-parastyle="FIR Body List">Design and operate key custody for the estate's cryptographic material under dual control, so that no single person can access or use production key material alone, with named custodians, recorded quorum operations and an auditable custody record. Own the delegated-authority model </span><span data-ccp-parastyle="FIR Body List">that keeps custody and out-of-hours cover available without depending on one individual.</span></span><span data-ccp-props="{"201341983":0,"335559738":145,"335559740":264}">&nbsp;</span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="49" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="8" data-aria-level="1"><span data-contrast="none"><span data-ccp-parastyle="FIR Body List">Harden the identity, certificate and secrets services to the same standard they enforce on everything else, and produce the access and certificate evidence ISO 27001, SOC 2 and enterprise customer due diligence </span><span data-ccp-parastyle="FIR Body List">require, for collation by the Service Delivery Manager</span><span data-ccp-parastyle="FIR Body List">.</span></span><span data-ccp-props="{"201341983":0,"335559738":145,"335559740":264}">&nbsp;</span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="49" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="9" data-aria-level="1"><span data-contrast="none"><span data-ccp-parastyle="FIR Body List">Provide the deepest technical expertise for identity, certificate and secrets faults, approve and review just-in-time access requests that require judgement beyond the standard workflow, and mentor engineers across the function on identity and secret management practice.</span></span><span data-ccp-props="{"201341983":0,"335559738":145,"335559740":264}">&nbsp;</span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="49" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"hybridMultilevel"}" data-aria-posinset="10" data-aria-level="1"><span data-contrast="none"><span data-ccp-parastyle="FIR Body List">Own the privileged access management model: just-in-time elevation tied to a change record, approval workflows, and recorded break-glass access for emergencies, designed so that no one approves their own access and privileged access to the trust plane itself is approved outside this role's own team.</span></span><span data-ccp-props="{"201341983":0,"335559738":145,"335559740":264}">&nbsp;</span></li> </ul> <p><strong><span data-co

Skills and categories

Eligibility checker
Check an offered salary against the published general salary floor for a sponsoring country.

Loading thresholds…

Apply for this role
Checking your session…
Or apply on the company site