Hardware Program Engineer: Security & Storage Platforms
Indexed description
About Cloudian
Cloudian builds HyperStore, a mature object storage platform deployed by hundreds of service providers as well as enterprise customers worldwide. We're now extending that platform to be the storage layer for AI, with a particular focus on inferencing. Our storage is NVIDIA certified and supports S3 RDMA, so it is suitable for high-performance use cases. We are an active participant in “next generation” AI storage projects, such as NVIDIA STX. With AI requiring increasing amounts of data, we are very well positioned as we can scale in capacity and performance, we provide all-flash storage as well as more cost-effective hybrid (flash+HDD), and we integrate effectively into the public cloud.
Our IP is software, but most customers deploy us as an appliance — which is where this role comes in.
About the Job
This role centers on security execution: CVE response, working the backlog from our AppSec tooling, and keeping our Common Criteria certification current. A hardware program component is layered in: bringing new ODM based storage products to market, driving qualification, and supporting our system integrator relationships. Roughly 75% security, 25% hardware.
This is a program manager/engineer role, not a product manager role. You're driving execution across engineering, security partners, ODM vendors, and integrators, not owning product roadmap or strategy. You need to be technically competent enough to get into the details yourself, not just coordinate people who are.
Core Responsibilities
- CVE Response: Monitor, triage, and assess the applicability of published CVEs against our software and dependency stack, and coordinate patch timelines with engineering owners. This is the largest single piece of the role.
- AppSec Triage: Own the backlog generated by our AppSec scanning tool (Aikido): validate findings, prioritize, and drive remediation with engineering. This work feeds directly into our ISO certification project.
- Common Criteria Certification: Maintain testing evidence for our Common Criteria certification, and work with the certification lab and internal engineering to close gaps.
- Security Coordination: Serve as the day to day point of contact for reactive security execution, escalating to the senior engineer who owns security strategy when judgment calls go beyond triage.
- Hardware Program Execution: Work with ODM partners to bring new storage appliance products to market, from spec through qualification to release, and support our system integrator relationships on qualification, integration testing, and issue resolution.
- Hardware Qualification & Vendor Relationships: Contribute hands-on to hardware and platform qualification (drives, controllers, chassis) as needed, and maintain working relationships with core component and technology vendors (drive, GPU/accelerator, memory, platform vendors) to stay current on roadmaps and qualification requirements.
Requirements
This role is not the right fit if:
- You have no hands-on storage or server hardware exposure at all, not even as an operator, administrator, or support engineer working with physical infrastructure. Some real exposure is required.
- You've never touched CVE triage, AppSec findings, or vulnerability remediation in any hands-on capacity. This is the majority of the role, and it needs to be a genuine strength, not something you're learning on the job.
- You're looking for a role that owns product roadmap or strategy, including security strategy. This is program execution: driving things to completion, not deciding direction. You'll be involved in strategy discussions, but that's not your main focus.
- You can't hold your own in Linux or basic scripting. You'll need it for the majority of the role.
- You don't use AI tools (Claude, Copilot, or similar) as a normal part of how you work. We expect this as standard practice for getting things done faster, not as an experiment you're trying out.
We're looking for:
- Security Baseline (Primary): Real, hands-on experience owning CVE triage and/or an AppSec findings backlog directly. You've made the call on whether something applied and what to do about it, not just generated or forwarded findings. This is the most important requirement in the role.
- Security Tooling & Compliance: Comfortable working with AppSec scanning tools (Aikido or similar) and contributing to certification efforts such as Common Criteria, FIPS, FedRAMP, or ISO. Direct evidence or testing experience is a plus.
- Storage & Hardware Background: Hands-on exposure to storage systems and physical hardware (server platforms, drives, controllers, or appliance deployments), gained through any of the following: bringing hardware products to market with an ODM partner, running vendor bake-offs, RFPs, or hardware qualification for a data center fleet at meaningful scale, or solid operational/administrative depth with physical storage or server hardware. We care more about the depth of hands-on exposure than which path got you there.
- Versatility: Comfortable owning whatever needs to be done, whether that's triage, vendor escalations, quals, or gaps nobody else has picked up, without needing the role scoped narrowly for you.
- AI-Fluent Execution: You use AI tools as a working habit, for triage, research, drafting, debugging, whatever the task calls for, to get more done faster. Baseline expected practice, not a bonus skill.
- AI Infrastructure (Nice to Have): Exposure to AI/ML infrastructure such as GPU servers, NVIDIA based platforms, or similar accelerated computing hardware is a plus given where our roadmap is headed, not required.
- Program Execution: A track record of driving cross-functional execution to completion, whether as a program manager, technical project manager, or engineer. A "Product Manager" title is not required.
- Tools: Jira; Aikido or comparable AppSec scanning tools a plus.
- Education: BS in a technical field, or equivalent practical experience.
- Travel: Up to 25%, for ODM, integrator, and partner engagements.
Please include brief answers to these questions in your cover letter or resume summary.
- Walk me through a specific server or storage hardware platform you selected or qualified — drive interface, controller, chassis. What was your actual role in that decision, and what was the hardest trade-off you had to make?
- Name an ODM, OEM, or system integrator you worked with directly — or, if your background is data-center side, a vendor bake-off or RFP you ran. What was the scope of that relationship, and describe a time something went wrong
- Walk me through a specific CVE, vulnerability, or AppSec finding you personally triaged. How did you decide whether it actually applied, and what call did you make?
- Tell me about a time you had to take on something completely outside your normal scope, with no one else to hand it to. What did you do, and how did you get up to speed?
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search