Verified current Job

Staff Platform Security Engineer (Security)

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Platform Security Engineer (Security) based

Job Remote Full source details
Jobgether Source published Sep 18, 2026 Verified 2 hours ago
✓ 100% verification score · Source: jobgether (lever) · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
EmploymentFull-time
Work modeRemote / location-flexible

Overview

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Platform Security Engineer (Security) based

Full job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Platform Security Engineer (Security) based in United States. As a Staff Platform Security Engineer, you will own security across critical AWS and Kubernetes infrastructure supporting products used by millions of people. You will work hands-on across cloud security, identity and access, workload isolation, CI/CD, software supply chains, and production systems. The role combines security architecture with practical engineering, requiring you to write code, build infrastructure controls, respond to incidents, and drive verified remediation. You will partner closely with infrastructure, SRE, developer experience, and product engineering teams to embed security into the platform without slowing delivery. You will also help shape an AI-native security function that uses automation and AI-assisted workflows to increase security coverage and response speed. This is a high-impact opportunity to influence architecture and strengthen the security of mission-critical systems in a fully remote environment.

Own and continuously improve security across a multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails. Secure production Kubernetes environments running on Amazon EKS, covering cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation. Design and implement least-privilege access models for engineers, services, and automation, including scoped, auditable, and time-bound access to sensitive production systems. Protect mission-critical infrastructure supporting systems that process sensitive information and high-value operations. Lead security architecture and design for new infrastructure, platform services, and major architectural changes. Build reusable infrastructure and policy-as-code controls using technologies such as Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation. Harden CI/CD and software supply chains, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and production access. Develop security automation that identifies and remediates cloud and Kubernetes risks at scale, using AI-assisted workflows where they can materially improve analysis, coverage, or response speed. Partner closely with Infrastructure, SRE, Developer Experience, and product engineering teams to establish practical platform security standards and drive adoption. Take ownership of security issues from initial investigation through implementation, remediation, and production verification. Contribute directly to incident response and security improvements while maintaining a balance between strong controls and engineering velocity. Requirements: 7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering discipline. Deep hands-on experience securing production AWS environments, including IAM and resource policies, workload identity, network security, secrets management, logging, organization-level controls, and common cloud security failure modes. Strong production Kubernetes security experience, preferably with Amazon EKS, including RBAC, workload identity, admission policies, network policies, pod security, secrets, and cluster hardening. Experience securing mission-critical systems where compromise, excessive privilege, or loss of availability could have significant customer or business consequences. Strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction across both human and machine access. Experience securing CI/CD pipelines and software supply chains, including GitHub Actions or comparable systems, build runners, workload federation, artifacts, and production deployment paths. Experience writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar technologies. Ability to write production-quality code and automation using a language such as TypeScript, Python, Go, or Rust. High degree of ownership and agency, with the ability to take ambiguous platform security problems from investigation through implementation and verified remediation. Strong communication skills and a proven ability to collaborate effectively with infrastructure and engineering teams while maintaining a high security standard. Experience with AWS Nitro Enclaves or other trusted execution environments is an advantage. Background securing financial, payments, wallet, custody, or other high-value transaction systems is a plus. Familiarity with AWS KMS, CloudHSM, cryptographic signing systems, key-management infrastructure, or secrets-management platforms is beneficial. Experience operating or securing multi-region AWS and Kubernetes environments at significant scale is a plus. Familiarity with Istio, PrivateLink, Transit Gateway, eBPF-based controls, or other cloud-native networking technologies is advantageous. Experience with GitHub OIDC, Argo CD, Helm, Crossplane, or Kubernetes-based infrastructure delivery is beneficial. Familiarity with security and observability platforms such as Wiz, Datadog, GuardDuty, Security Hub, or CloudTrail is a plus. Experience building policy-as-code, automated remediation, or security tooling used across large engineering organizations is valuable. Familiarity with blockchain infrastructure or self-custodial wallet architecture is an advantage. Benefits: $200,000–$250,000 USD target base salary, with final compensation influenced by skills, relevant experience, interview performance, and market factors such as location. Equity participation. Eligibility for a performance bonus program. Comprehensive medical, dental, and vision insurance with 100% coverage. Stipend for an ideal remote-work setup. Flexible working hours. Fully remote and supportive work environment. Unlimited vacation. 401(k) retirement plan. Monthly wellness benefit. Weekly meal benefit. Global company off-sites. Opportunity to secure AWS and Kubernetes infrastructure supporting products used by millions of people. High-impact work spanning cloud identity, production access, workload isolation, software supply chains, and mission-critical infrastructure. Opportunity to build security controls directly into the platform rather than operating solely in an advisory or review capacity. Ability to influence architecture early and own security improvements through implementation and production verification. Opportunity to contribute to an AI-native security team focused on engineering, automation, and scalable security operations.

Tips for this job

Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

laptop-ats-crawler v3

Original authoritative source

Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

jobgether (lever) ↗

Browse current Job and Scholarship listings from jobgether (lever) →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books