1

Kernel Security Engineer Jobs (NOW HIRING)

Teams at Cash App, Framer, and 7000+ others use Kernel for deep research, QA automation, and real ... About the role We're hiring a Browser Security Engineer to harden and extend our Chromium-based ...

Developer security and supply chain * Build and advance our developer security program by embedding ... Experience building runtime security monitoring using eBPF or kernel security policies What we ...

As a Security Engineer at Nous Research, you'll own security end-to-end across our infrastructure ... Secure the Hermes Agent platform across sandboxing, kernel-level file system and network isolation ...

Senior Cloud Security Engineer

Mountain View, CA · On-site

$136K - $186K/yr

They are seeking a highly skilled Senior Cloud Security Engineer to architect and secure their ... kernel security policies Company : Endlessly adaptable. Always reliable. Through the endless ...

next page

Showing results 1-20

Kernel Security Engineer information

See salary details

$61.5K

$152.8K

$205.5K

How much do kernel security engineer jobs pay per year?

As of Sep 10, 2026, the average yearly pay for kernel security engineer in the United States is $152,773.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $158,500.00 per year, depending on experience, location, and employer.

What does a kernel security engineer do?

A Kernel Security Engineer is responsible for designing, implementing, and maintaining security features within an operating system’s kernel. This role involves identifying vulnerabilities, developing patches, and ensuring that the kernel is protected against various threats such as privilege escalation, code execution, and other attacks. Kernel Security Engineers often work closely with software developers and security teams to create secure architectures and respond to security incidents. Their work is crucial in maintaining the integrity and security of systems, especially in environments where security is a top priority.

What are some common challenges faced by kernel security engineers when working with large codebases?

Kernel Security Engineers often work with complex and extensive codebases, which can make identifying and fixing security vulnerabilities challenging. Navigating legacy code, understanding intricate system interactions, and ensuring compatibility with various hardware architectures require strong analytical skills and attention to detail. Collaboration with other engineers, such as kernel developers and security researchers, is essential for successfully implementing security patches and staying updated on emerging threats. A proactive approach to code review and continuous learning is key to overcoming these challenges.

What are the key skills and qualifications needed to thrive as a kernel security engineer, and why are they important?

To thrive as a Kernel Security Engineer, you need deep knowledge of operating system internals, C/C++ programming, and experience with vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with Linux kernel development tools, debugging systems like GDB, and certifications such as OSCP or CEH are typically valuable. Analytical thinking, attention to detail, and strong problem-solving skills enable you to identify threats and create robust security solutions. These competencies are critical to protect the core of computing systems against sophisticated attacks and maintain system integrity.

What are popular job titles related to Kernel Security Engineer jobs?

For Kernel Security Engineer jobs, the most frequently searched job titles are:

Infographic showing various Kernel Security Engineer job openings in the United States as of August 2026, with employment types broken down into 84% Full Time, 13% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $152,773 per year, or $73.4 per hour.

Staff Product Security Engineer, Secure Design (Kernel and Virtualization)

Seattle, WA • Hybrid

DigitalOcean
Software Development • 501 - 1,000 employees

$175K - $190K/yr

Full-time

Re-posted 17 days ago


Job description

We're looking for a Staff Product Security Engineer who is passionate about partnering with engineers to assess and mitigate the security risk of our virtualization stack.

You'll own the security risk posture for our virtualization stack. You'll get there by building the frameworks the org uses to reason about hypervisor risk - systematic threat models that surface risks, shared rubrics for assessing their impact and likelihood, and clear ways of communicating them to security, kernel, virtualization, and provisioning teams. From there, you'll own the response: designing and proposing defense-in-depth mitigations and driving their implementation.

As a member of the Product Security team, you will report to the Manager of Secure Design. Our Secure Design team enables DigitalOcean to build secure-by-design products. We leverage strong relationships with both product teams and the rest of security engineering to be successful. The team's scope is primarily focused on reviewing early-stage decisions, developing threat models, scaling impact via automation, curating security patterns, authoring security guidance, training, and championing security initiatives. 

What you'll do:

Propose and implement mitigations and defense-in-depth to threats discovered through threat modeling the virtualization stack (90%)

  • Provide deep technical expertise in systems architecture, kernel security features and network architecture to build out a threat model for our virtualization stack
  • Identify the trade-offs of different solutions and recommend the efficient design to achieve both functional goals and security requirements. We do not deliver mandates; we work alongside cross-functional partners to find mutually beneficial solutions.
  • Collaborate with development teams to implement remediations and defense in depth to protect DigitalOcean's customers' workloads.

Cultivate and promote a security culture (10%)

  • Mentor software engineering teams in security best practices.
  • Help oversee our vulnerability management program (we call it security debt).
  • Help DigitalOcean engineers understand how security events impact them. Do they need to worry about the next Redfish or Copy Fail CVEs? How does RetBleed impact DigitalOcean's fleet?
What you'll add to DigitalOcean:

Required qualifications:

  • Deep familiarity with at least one kernel security feature (ex: AppArmor, SELinux, Landlock, etc.) 
  • Capable of assessing and understanding the performance implications of code changes to virtualization stacks (especially in Qemu and KVM), built from hands-on experience. Experience 
  • A record of partnering with internal engineering teams to tackle security problems across an entire stack with empathy and creativity. Engineering teams are our partners, not our adversaries.
  • Ability to clearly communicate security topics and vulnerability classes (e.g. memory corruption, privilege escalation, TOCTOU, etc) and ability to provide actionable direction to product teams.
  • Working knowledge of modern development concepts (virtualized environments, containerization, continuous integration + delivery).

Preferred qualifications:

  • 5+ years of writing systems level code (embedded systems, kernel, assembly or similar).
  • Experience guiding software teams on secure architecture design.
  • Written code for an embedded system (raspberry pi, arduino, etc).
  • Experience building or reviewing threat models and ability to craft malicious user, attacker, and abuse/misuse cases.
  • An understanding of patches and mitigations for hardware side-channel attacks.
  • Familiarity with object oriented and functional programming concepts, particularly with languages such as Go, Rust, or C.
Compensation Range: 
  • $175,000 - $190,000

*This is a hybrid role

JR: 2026-8011

#LI-Hybrid