Senior Data Center Security Specialist
Lucid Computing Senior Data Center Security Specialist
The Role
Lucid Computing, in partnership with the Research Institutes of Sweden (RISE), is building and operating an adversarial testbed for developing and red-teaming AI compute verification solutions. The premise of the project is that verification claims — where AI compute runs, how it is used, what model is loaded — are only as good as the adversarial attacks they can withstand. Our job is to build verification solutions that can survive such attacks.
Every solution ultimately rests on a physical and operational security foundation. Components like network taps, randomized inference routers, TEEs and assurance nodes are all in-path devices whose guarantees evaporate if an adversary can bypass, substitute, or tamper with them — or simply walk undeclared hardware into the room. Physical security is a prerequisite: cameras, custom server enclosures, tamper-evident mechanisms, random spot inspections, countermeasures against undeclared wireless components, controlled installation and maintenance procedures, and chain-of-custody for every security-relevant device are all in-scope. The successful candidate will collaborate with the rest of the team to utilize components like these to develop the physical security layer of our team’s verification designs.
This is not a conventional data center security job. You will not be running a badge program or maintaining a compliance checklist against a static standard. You will be designing security protocols for a threat model most facilities never contemplate — a well-resourced, covert adversary who may be the facility operator themselves — and then watching a highly-sophisticated, independent red team try to break what you built, with the results published either way, negative findings included. The end goal of this work is to produce technical verification designs that can enable nation-states and AI companies to coordinate around policies and standards that support AI security at a global scale. The role will reward candidates who find that prospect energizing.
What You'll Do
At the design level, you will be the physical and operational security voice inside a multidisciplinary team of hardware engineers, network engineers, cryptographers, ML researchers, and governance researchers. When the team debates a new verification architecture, you are the person who asks how the network devices are installed without a trusted installer, how we detect a hidden NIC inside a GPU server, what an inspection regime for declared local storage actually looks like in practice, and what it costs. You will contribute original security designs of your own — we expect the successful candidate to invent, not just review.
At the physical level, you will implement and operate these protocols in real experiments on a real-world GPU cluster, overseeing secure installation of in-path verification devices alongside live workloads. The installation-assurance documentation, inspection methodologies, and physical threat models you produce will be published as part of an open reference architecture, intended to inform how governments and AI labs approach verification. You should be excited to have your work scrutinized publicly and improved by that scrutiny.
Required Skills & Background
Hands-on experience securing operational AI/GPU data centers. You have designed, implemented, or run physical and operational security for facilities hosting large-scale accelerated compute.
Deep expertise in physical security controls and operations: access control and zoning, surveillance and camera coverage design, intrusion detection, tamper-evident seals and enclosures, secure racks/cages, visitor and vendor escort procedures, and guard/inspection operations.
Threat modeling against sophisticated adversaries, including insider threats and well-resourced external actors.
Hardware lifecycle and chain-of-custody security: secure receipt, provenance verification, installation, maintenance, and decommissioning of security-relevant hardware; experience designing procedures that remain trustworthy when individual staff or vendors are not.
Working fluency in data center infrastructure — power, cooling, structured cabling, network topology, out-of-band management — sufficient to collaborate credibly with network and hardware engineers and to spot where physical and logical security assumptions interact.
Experience with adversarial testing of physical security: running, supporting, or remediating findings from physical penetration tests, red-team exercises, or hostile audits of facilities.
Strong security writing. You can produce clear threat models, SOPs, inspection protocols, and assurance documentation that a third party could execute and an external expert could critique.
Demonstrated creativity and first-principles thinking. Evidence that you have designed or are capable of designing novel security mechanisms.
Nice-to-Haves
Experience in cleared, regulated, or high-assurance facilities: SCIF construction/accreditation (ICD 705 or national equivalents), TEMPEST/emanation security, defense or intelligence-community data centers, or financial-exchange-grade facilities.
Side-channel and covert-channel defense experience: RF/acoustic/power-line emanation assessment, shielding, filtering, jamming, or detection of undeclared wireless devices.
Hardware and firmware security knowledge: JTAG/SPI-flash attack and defense, BMC/DC-SCM security, firmware attestation, hardware roots of trust, or supply-chain attack analysis.
Background in arms-control or safeguards verification — e.g., IAEA-style inspection regimes, tamper-indicating devices, containment and surveillance, information barriers, or chain-of-custody in bilateral low-trust settings. This project borrows heavily from that intellectual tradition.
Familiarity with the emerging AI verification and compute governance literature (workload classification, network taps, recomputation, flexible hardware-enabled guarantees) or a demonstrated ability to come up to speed on it quickly.
Experience with relevant standards and frameworks (EN 50600, TIA-942, ISO 27001 physical/environmental controls, SOC 2) and, more importantly, good judgment about where they stop being useful for our threat model.
Understanding of confidential computing and attestation (TEEs, measured boot) at the level needed to reason about how physical security composes with hardware-rooted evidence.
Experience designing insider-threat and personnel-security programs (two-person integrity, background/vetting processes, diverse-team inspection protocols).
Publication or public-speaking experience — this role's outputs will be published, and we value people who can represent the work to labs, governments, and the research community.
EU work authorization or an existing basis for working in Sweden.
Ability to occasionally work on-site in Sweden (installation campaigns, inspections, and red-team cycles at the RISE cluster).
Collaboration in research or R&D environments, and comfort working with ambiguity, iteration, and public critique of your work.
Eligibility for, or history of holding, a national security clearance.
Lucid Computing will publish its results — including negative findings — under a pre-agreed protocol with RISE. Candidates should be comfortable with, and ideally enthusiastic about, building security in the open.