Cloudian Inc
Senior Security Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
About Cloudian
Cloudian builds HyperStore, a leading object storage platform deployed by hundreds of service providers and enterprise customers worldwide. We're extending that platform to be the storage layer for AI, with a particular focus on inferencing. Our storage is NVIDIA-certified and supports S3 RDMA, making it well-suited to high-performance use cases. We are an active participant in next-generation AI storage projects such as NVIDIA STX. As AI workloads demand more data, we're well positioned: we scale in both capacity and performance, offer all-flash as well as more cost-effective hybrid (flash+HDD) storage, and integrate cleanly into the public cloud.
About the Job
This is a senior, hands-on security role at the center of how we protect HyperStore — a platform trusted by hundreds of customers, and increasingly by the AI workloads running on top of it. You'll own CVE response, drive our AppSec program, manage security certifications (like Common Criteria, FIPS 140-3, SOC2), and work closely with product leaders and other engineers to drive our overall security strategy.
Beyond the core security work, you'll get real exposure to other parts of the business as they come up. Right now that includes a meaningful chunk of hardware platform work — helping bring new ODM-based storage products to market, contributing to hardware qualification, and building relationships with our system integrators and technology vendors. The mix evolves over time; that variety is part of what makes this role interesting rather than static.
Core Responsibilities
- CVE Response: Monitor, triage, and assess the applicability of published CVEs against our software and dependency stack, and coordinate patch timelines with engineering owners.
- AppSec Triage: Own the backlog generated by our AppSec scanning tool (Aikido): validate findings, prioritize, and drive remediation with engineering. This work feeds directly into our ISO certification project.
- Common Criteria Certification: Maintain testing evidence for our Common Criteria certification, and work with the certification lab and internal engineering to close gaps.
- Security Planning & Roadmap Input: Partner with our senior security engineer on how we prioritize, sequence certification work, and evolve our security posture. This is a genuine input role, not just a hand-off point — your thinking shapes the plan, not just the execution of it.
- Hardware & Platform Work: Contribute hands-on to hardware and platform qualification (drives, controllers, chassis), work with ODM partners bringing new storage appliances to market, support our system integrator relationships, and stay current on core component and technology vendor roadmaps (drive, GPU/accelerator, memory, platform vendors).
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Requirements
This role is not the right fit if:
- You have no hands-on storage or server hardware exposure at all, not even as an operator, administrator, or support engineer working with physical infrastructure. Some real exposure is required.
- You've never touched CVE triage, AppSec findings, or vulnerability remediation in any hands-on capacity. This is the majority of the role, and it needs to be a genuine strength, not something you're learning on the job.
- You can't hold your own in Linux or basic scripting. You'll need it for the majority of the role. If most of the below sounds like you, we'd like to talk — even if you don't check every box.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
We're looking for:
- Security Baseline (Primary): Real, hands-on experience owning CVE triage and/or an AppSec findings backlog directly. You've made the call on whether something applied and what to do about it, not just generated or forwarded findings. This is the most important requirement in the role.
- Security Tooling & Compliance: Comfortable working with AppSec scanning tools (Aikido or similar) and contributing to certification efforts such as Common Criteria, FIPS, FedRAMP, or ISO. Direct evidence or testing experience is a plus.
- Storage & Hardware Background: Hands-on exposure to storage systems and physical hardware (server platforms, drives, controllers, or appliance deployments), gained through any of: bringing hardware products to market with an ODM partner; running vendor bake-offs, RFPs, or hardware qualification for a data center fleet at meaningful scale; or solid operational/administrative depth with physical storage or server hardware. Depth of hands-on exposure matters more than which path got you there.
- Planning Instinct: A track record of contributing to planning, not just being handed a plan — you ask why, push back when something doesn't make sense, and help shape priorities rather than just working through them.
- Versatility: Comfortable owning whatever needs to be done — triage, vendor escalations, quals, gaps nobody else has picked up — without needing the role scoped narrowly for you.
- AI-Fluent Execution: You use AI tools as a working habit — for triage, research, drafting, debugging, whatever the task calls for — to get more done faster. This is baseline expected practice here, not a bonus skill.
- AI Infrastructure (Nice to Have): Exposure to AI/ML infrastructure — GPU servers, NVIDIA-based platforms, or similar accelerated computing hardware — is a plus given where our roadmap is headed, not required.
- Certification Experience: Direct experience with Common Criteria, FIPS, or FedRAMP evidence/testing is a plus, not required.
- Tools: Jira; Aikido or comparable AppSec scanning tools a plus.
- Education: BS in a technical field, or equivalent practical experience.
- Travel: Up to 25%, for ODM, integrator, and partner engagements.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location