Logo for Verda

Linux Systems Engineer – Identity, PKI & Security (IDM)

Role overview

Qualifications

  • Deep, hands-on experience managing Linux operating systems at scale
  • Operational expertise using SaltStack and/or Ansible
  • Practical experience implementing SSH CAs and automated TLS issuance
  • Strong understanding of identity protocols (OIDC, OAuth2, WebAuthn/FIDO2)

Responsibilities

  • Own the Linux Identity Layer by managing Kanidm as the central identity source
  • Design, deploy, and automate short-lived SSH Certificate Authority workflows
  • Use SaltStack and Ansible for declarative configuration management
  • Partner with the Security team to implement compliance and security requirements

Key facts

  • Remote from: European Union
  • Full time
  • Application Security Engineer
  • English

Hard skills

Other skills

  • Problem Solving
  • Collaboration

About the company

Verda logo

Verda

Computer Software / SaaS

Verda Cloud Oy is a cloud service provider geared towards AI, providing raw computational power at affordable rates.

Company details

Company typeSME
IndustryComputer Software / SaaS
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Imagine a future where everyone has instant, low-cost access to intelligence. We’re building a fully featured European AI cloud - with everything one needs to train, experiment with, and deploy AI models. In addition, our GPUs run on 100% renewable energy.

We’re ambitious, curious, and gutsy doers. We practice a low hierarchy across the company and high morale in our teams. We’ve already achieved a lot, yet we’re only getting started. Now it’s your chance to join the ride. We offer more than just the job - we offer a career-defining opportunity to be part of building something big!

Join Verda while it’s still being built - not once it’s finished.

About the role

In this role, you will operate as a Linux Systems Engineer taking full ownership of how identities, credentials, certificates, and secrets are provisioned, authenticated, and distributed across our cloud infrastructure. You will bridge the gap between strict security policies and Linux-native infrastructure—building automated pipelines that replace legacy directory systems with modern, code-driven identity architectures.

You’ll serve as the primary engineering liaison to our Security team, turning threat models and compliance rules into production-grade systems code.

Your Responsibilities

  • Own the Linux Identity Layer: Champion and manage Kanidm as our central identity source of truth. Architect and support client-side Linux host integrations using SSSD, PAM, and NSS modules for seamless user lifecycle and access management.

  • Architect SSH & PKI Security: Design, deploy, and automate short-lived SSH Certificate Authority (SSH CA) workflows for host and user authentication, paired with step-ca for internal PKI and OpenBao for decentralized secrets management.

  • Automate Infrastructure as Code: Use SaltStack and Ansible to enforce 100% declarative configuration management across identity services, SSSD configs, OpenSSH daemons, and system access policies.

  • Act as the Security Engineering Liaison: Partner directly with our Security team to translate compliance frameworks, zero-trust requirements, and threat models into hardened, automated Linux infrastructure.

  • Federate Authentication: Architect, deploy, and troubleshoot OIDC and OAuth2 integrations across our internal engineering toolchain, anchoring host-level access back to our central identity platform.

Your key competencies

  • Linux Systems Engineering Core: Deep, hands-on experience managing Linux operating systems at scale (RHEL/Debian families), with explicit knowledge of the Linux authentication ecosystem (SSSD, PAM, NSS, OpenSSH).

  • Configuration Management Mastery: Operational expertise using SaltStack and/or Ansible to manage system state, deploy identity agents, and maintain zero configuration drift.

  • PKI & SSH Certificate Infrastructure: Practical experience implementing SSH CAs, short-lived host/user certificates, and automated internal TLS issuance.

  • Modern Identity Architecture: Strong understanding of identity protocols (OIDC, OAuth2, WebAuthn/FIDO2, POSIX mapping) and experience building or migrating identity sources of truth.

  • Security & Systems Mindset: The ability to translate high-level security policies into precise system configurations, script automation, and actionable infrastructure code.

    Nice-to-Haves

  • Direct production experience deploying, operating, or migrating to Kanidm, OpenBao, or step-ca.

  • Experience migrating environments away from legacy Active Directory / Windows domain architectures to Linux-native identity stacks.

  • Experience writing custom SSSD plugins, PAM modules, or high-velocity Python/Rust tooling for system administration.

Why Verda

  • Cash + equity compensation along with various fringe benefits.

  • Profitable operations with rapid, sustained growth.

  • 31 nationalities, with 6 different ones on the management team.

  • An opportunity to make a clear impact and work alongside world-class engineers, researchers, and partners across the global AI ecosystem.

Practicalities

  • Work mode: Remote (EU)

  • Employment type: Full-time, permanent

  • Start date: As soon as possible

What's next

We’re building fast and this role needs the right person behind it. There’s no artificial deadline, but when we find who we’re looking for, we move.

If this sounds like your next move, apply now.

Please submit your application through our Careers page. We don’t accept applications sent by email nor through agencies.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Application Security Engineer Related jobs

Other jobs at Verda

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.