
Hover or tap a row for full statistics (EUR / month on this chart).
Salary analysis
Compared with the selected benchmark ("All roles in Remote - Europe"), this listing's salary midpoint is about 94% lower. The offer sits below the benchmark range (€1,692–€11,759). The listed pay band (€307–€500) is tighter than the benchmark, which suggests lower salary variability. This benchmark is based on 22 comparable listings.
| Market | Lower bound (25th percentile) | Median | Upper bound (75th percentile) |
|---|---|---|---|
| All roles in Remote - Europe | €1,692/per month | €4,842/per month | €11,759/per month |
| Pay in our data — not quoted in ad (Mid-Level) | €307/per month | €404/per month | €500/per month |
Imagine a future where everyone has instant, low-cost access to intelligence. We’re building a fully featured European AI cloud - with everything one needs to train, experiment with, and deploy AI models. In addition, our GPUs run on 100% renewable energy. We’re ambitious, curious, and gutsy doers. We practice a low hierarchy across the company and high morale in our teams. We’ve already achieved a lot, yet we’re only getting started. Now it’s your chance to join the ride. We offer more than just the job - we offer a career-defining opportunity to be part of building something big! Join Verda while it’s still being built - not once it’s finished. About the role In this role, you will operate as a Linux Systems Engineer taking full ownership of how identities, credentials, certificates, and secrets are provisioned, authenticated, and distributed across our cloud infrastructure. You will bridge the gap between strict security policies and Linux-native infrastructure—building automated pipelines that replace legacy directory systems with modern, code-driven identity architectures. You’ll serve as the primary engineering liaison to our Security team, turning threat models and compliance rules into production-grade systems code. Your Responsibilities - Own the Linux Identity Layer: Champion and manage Kanidm as our central identity source of truth. Architect and support client-side Linux host integrations using SSSD, PAM, and NSS modules for seamless user lifecycle and access management. - Architect SSH & PKI Security: Design, deploy, and automate short-lived SSH Certificate Authority (SSH CA) workflows for host and user authentication, paired with step-ca for internal PKI and OpenBao for decentralized secrets management. - Automate Infrastructure as Code: Use SaltStack and Ansible to enforce 100% declarative configuration management across identity services, SSSD configs, OpenSSH daemons, and system access policies. - Act as the Security Engineering Liaison: Partner directly with our Security team to translate compliance frameworks, zero-trust requirements, and threat models into hardened, automated Linux infrastructure. - Federate Authentication: Architect, deploy, and troubleshoot OIDC and OAuth2 integrations across our internal engineering toolchain, anchoring host-level access back to our central identity platform. Your key competencies - Linux Systems Engineering Core: Deep, hands-on experience managing Linux operating systems at scale (RHEL/Debian families), with explicit knowledge of the Linux authentication ecosystem (SSSD, PAM, NSS, OpenSSH). - Configuration Management Mastery: Operational expertise using SaltStack and/or Ansible to manage system state, deploy identity agents, and maintain zero configuration drift. - PKI & SSH Certificate Infrastructure: Practical experience implementing SSH CAs, short-lived host/user certificates, and automated internal TLS issuance. - Modern Identity Architecture: Strong understanding of identity protocols (OIDC, OAuth2, WebAuthn/FIDO2, POSIX mapping) and experience building or migrating identity sources of truth. - Security & Systems Mindset: The ability to translate high-level security policies into precise system configurations, script automation, and actionable infrastructure code. Nice-to-Haves - Direct production experience deploying, operating, or migrating to Kanidm, OpenBao, or step-ca. - Experience migrating environments away from legacy Active Directory / Windows domain architectures to Linux-native identity stacks. - Experience writing custom SSSD plugins, PAM modules, or high-velocity Python/Rust tooling for system administration. Why Verda - Cash + equity compensation along with various fringe benefits (e.g., healthcare, lunch, wellbeing, etc.). - Profitable operations with rapid, sustained growth. - 31 nationalities, with 6 different ones on the management team. - An opportunity to make a clear impact and work alongside world-class engineers, researchers, and partners across the global AI ecosystem. Practicalities - Work mode: Remote (EU) - Employment type: Full-time, permanent - Start date: As soon as possible What's next We’re building fast and this role needs the right person behind it. There’s no artificial deadline, but when we find who we’re looking for, we move. If this sounds like your next move, apply now. Please submit your application through our Careers page. We don’t accept applications sent by email nor through agencies.
Job Details
Responsibilities
- Manage Kanidm as the central identity source of truth
- Architect and support client-side Linux host integrations using SSSD, PAM, and NSS modules
- Design, deploy, and automate short-lived SSH Certificate Authority (SSH CA) workflows
- Implement internal PKI with step-ca and decentralized secrets management with OpenBao
- Use SaltStack and Ansible for declarative configuration management of identity services and system access policies
- Translate compliance frameworks and threat models into hardened, automated Linux infrastructure
- Architect and troubleshoot OIDC and OAuth2 integrations across the internal engineering toolchain
Requirements
- Deep, hands-on experience managing Linux operating systems at scale (RHEL/Debian families)
- Explicit knowledge of the Linux authentication ecosystem (SSSD, PAM, NSS, OpenSSH)
- Operational expertise using SaltStack and/or Ansible to manage system state and deploy identity agents
- Practical experience implementing SSH CAs, short-lived host/user certificates, and automated internal TLS issuance
- Strong understanding of identity protocols (OIDC, OAuth2, WebAuthn/FIDO2, POSIX mapping)
- Ability to translate high-level security policies into precise system configurations and infrastructure code
Skills & Technologies

Related Opportunities
Discover more opportunities that match your interests and skills