Chief Technology Officer
- $150k – $200k • 0.5% – 2.0%
- |Remote () • +12
- |5 years of exp
- |Full Time
Onsite or remote
Not Available
About the job
The Role
We are seeking a Chief Technology Officer (CTO) who pairs high-level architectural vision with hands-on bare-metal execution. You will lead technical strategy, manage external data center and VAR vendor relationships, and build the core automation that powers our sovereign compute platform. You will not be racking servers or soldering motherboards. You will be the architectural brain and execution authority over our Infrastructure-as-Code (IaC), remote hardware provisioning, and security layers.
What You’ll Do
Architect Infrastructure-as-Code (IaC): Design zero-touch bare-metal provisioning, PXE boot pipelines, TPM/LUKS encryption key unsealing policies, and custom OS deployment artifacts.
Remote Out-of-Band Management: Orchestrate high-density System76 Ibex GPU servers remotely via BMC/IPMI and Redfish APIs over encrypted management VLANs.
Kernel & Perimeter Hardening: Replace legacy wrappers (ufw) with native declarative nftables kernel firewall configurations, ensuring zero container bridge bypasses and atomic packet filtering.
AI Security & Sandboxing: Deploy agentic execution runtimes (NVIDIA OpenShell / NemoClaw) and integrate in-line AI trust/guardrail frameworks (Aiceberg).
Zero-Trust Mesh & Audit Isolation: Configure Headscale/Tailscale WireGuard overlay networks and containerized PostgreSQL audit trails to enforce microsecond-timestamped GxP records.
Vendor & Ops Governance: Partner with our COO to set technical SOWs, SLA expectations, and operational handoffs for Smart Hands (Silverback) and VAR/EUC staging partners (Park Place).
Technical Attestation: Generate signed, automated security proof and compliance reports (CIS baselines) for enterprise client legal and security reviews.
What We’re Looking For
System-Level Engineering: Deep experience with Linux kernel primitives, declarative nftables, NUMA node affinity, PCIe Gen 5 topologies, and IPMI 2.0 / Redfish APIs. CUDA/MXL/ROCm-aware systems engineer.
Hardware-Rooted Security: Practical mastery of TPM 2.0, LUKS disk encryption, AMD SEV / Intel SGX Confidential Computing enclaves, and coreboot/open firmware architecture.
Container & Mesh Networking: Hands-on expertise with Docker networking, Headscale/Tailscale WireGuard overlays, and containerized database management (PostgreSQL).
Leadership & Vendor Alignment: Proven ability to manage technical deliverables, set engineering standards, and interface with enterprise vendors and client executive teams.
Tech Stack
Linux (Pop!_OS / Ubuntu LTS), nftables, IPMI / Redfish API, Ansible, Headscale / WireGuard, Docker, NVIDIA OpenShell / NemoClaw, AnythingLLM, PostgreSQL, Python, Bash.
About the company
Similar Jobs









