Staff Security Engineer - Platform

On

Zürich

Vor Ort

CHF 180.000 - 270.000

Vollzeit

Vor 8 Tagen

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

On is seeking a Staff Security Engineer - Platform in Zürich to turn security requirements into implemented controls across platform, CI/CD, and cloud environments. You will embed security into design, build secure pipelines, and reduce risk with practical engineering solutions.

You will contribute directly to code, infrastructure, and security automation, partnering with Engineering, AI, Platform & Ops, and Cloud Security teams.

Qualifikationen

  • 12+ years of experience in security engineering, platform security, cloud security, DevSecOps, application security, or infrastructure security
  • Hands-on experience contributing to engineering workflows using Git, pull requests, code reviews, CI/CD pipelines, automation, or infrastructure-as-code
  • Experience with cloud environments, ideally including Google Cloud Platform; understand cloud IAM, network exposure, platform security, and secure configuration patterns
  • Practical experience with vulnerability remediation and moving from finding to fix, including validating closure and preventing recurrence
  • Familiarity with CI/CD security controls such as secrets scanning, dependency scanning, SAST, infrastructure-as-code scanning, policy-as-code, or secure build pipelines
  • Knowledge of identity and access security concepts, including least privilege, privileged access, service accounts, non-human identities, temporary access, and credential rotation
  • Ability to translate threat models, risk scenarios, and architecture requirements into concrete technical controls
  • Curiosity about emerging AI security risks and securing modern development workflows involving AI-generated code, coding agents, MCP servers, and automation
  • Strong collaboration skills to build trust with Engineering, AI, Platform & Ops, Cloud Security Architecture, Cyber Defence, and GRC teams
  • Clear communication with technical and non-technical stakeholders, focusing on practical risk reduction
  • Pragmatic mindset balancing speed, security, engineering quality, and business impact

Aufgaben

  • Work side-by-side with Engineering, AI, Platform & Ops, and Cloud Security Architecture teams to translate security requirements, threat models, and vulnerability findings into practical engineering outcomes
  • Contribute hands-on to platform, CI/CD, infrastructure-as-code, and security-control repositories through pull requests, configuration changes, automation, and policy-as-code
  • Build and improve scalable security guardrails across the software delivery lifecycle, including secrets scanning, dependency scanning, infrastructure-as-code checks, secure build controls, and AI development workflows
  • Partner with engineering teams to remediate vulnerabilities, reduce attack surface, and prevent recurring findings through direct fixes, paired engineering work, or automated controls
  • Strengthen identity and access security for both human and non-human identities, including service accounts, CI runners, automation workflows, coding agents, MCP servers, and bots
  • Support secure-by-design reviews and threat modelling for cloud, platform, identity, CI/CD, and AI-enabled development, ensuring risks are addressed before implementation starts
  • Participate in operational ownership for security-relevant infrastructure and controls you materially contribute to, including root-cause analysis and incident remediation where needed

Kenntnisse

Security engineering
DevSecOps
Threat modelling
Vulnerability remediation
Cloud security
CI/CD security

Tools

Git
CI/CD pipelines
Infrastructure as Code
Security automation

Jobbeschreibung

In short

At On, our technology moves as fast as our runners: always evolving, always pushing boundaries. We're building a world-class platform to ignite the human spirit through movement, and our Information Security team is the trusted guardian of that mission. Join a collaborative team of curious minds who believe security should not stop at recommendations. We are moving security closer to engineering — into the code, pipelines, platforms, cloud environments, and identity systems where risks are created and remediated. We are looking for a Staff Security Engineer - Platform who wants to work side-by-side with Engineering, AI,Platform & Ops, and Cloud Security Architecture teams. This is a deeply hands-on role for someone who can open pull requests, build guardrails, remediate vulnerabilities, reduce attack surface, and help make secure engineering the default way of working at On. This role is for someone who sees security not as a gate, but as a force multiplier for engineering excellence.

Your mission

As a Staff Security Engineer - Platform your mission is to turn security requirements into implemented controls. You will work directly with Engineering, AI, Platform & Ops, and Cloud Security Architecture teams to embed security into how platforms and products are designed, built, deployed, and operated. You will move beyond advisory security by contributing directly to platform repositories, CI/CD pipelines, infrastructure-as-code, identity controls, and security automation. Your success will be measured by risk reduction: merged fixes, fewer repeat findings, stronger guardrails, and a more resilient engineering ecosystem.

  • Work side-by-side with Engineering, AI, Platform & Ops, and Cloud Security Architecture teams to translate security requirements, threat models, and vulnerability findings into practical engineering outcomes
  • Contribute hands-on to platform, CI/CD, infrastructure-as-code, and security-control repositories through pull requests, configuration changes, automation, and policy-as-code
  • Build and improve scalable security guardrails across the software delivery lifecycle, including secrets scanning, dependency scanning, infrastructure-as-code checks, secure build controls, and AI development workflows
  • Partner with engineering teams to remediate vulnerabilities, reduce attack surface, and prevent recurring findings through direct fixes, paired engineering work, or automated controls
  • Strengthen identity and access security for both human and non-human identities, including service accounts, CI runners, automation workflows, coding agents, MCP servers, and bots
  • Support secure-by-design reviews and threat modelling for cloud, platform, identity, CI/CD, and AI-enabled development, ensuring risks are addressed before implementation starts
  • Participate in operational ownership for security-relevant infrastructure and controls you materially contribute to, including root-cause analysis and incident remediation where needed
Your story

You are a hands-on security engineer who enjoys working closely with engineering & AI teams, platforms, code, and infrastructure. You are not satisfied with writing recommendations and waiting for someone else to implement them. You like to build, fix, automate, and improve the system at the source.

You combine strong security judgment with practical engineering skills and know how to make security controls work in real-world development environments.

  • You bring 12+ years of experience in security engineering, platform security, cloud security, DevSecOps, application security, or infrastructure security
  • You have hands-on experience contributing to engineering workflows using Git, pull requests, code reviews, CI/CD pipelines, automation, or infrastructure-as-code
  • You are comfortable working with cloud environments, ideally including Google Cloud Platform, and understand cloud IAM, network exposure, platform security, and secure configuration patterns
  • You have practical experience with vulnerability remediation and know how to move from finding to fix, including validating closure and preventing recurrence
  • You understand CI/CD security and have experience with controls such as secrets scanning, dependency scanning, SAST, infrastructure-as-code scanning, policy-as-code, or secure build pipelines
  • You are familiar with identity and access security concepts, including least privilege, privileged access, service accounts, non-human identities, temporary access, and credential rotation
  • You are able to translate threat models, risk scenarios, and architecture requirements into concrete technical controls that engineers can implement and operate
  • You are curious about emerging AI security risks and motivated to secure modern development workflows involving AI-generated code, coding agents, MCP servers, and automation
  • You are a natural collaborator who can build trust with Engineering, AI, Platform & Ops, Cloud Security Architecture, Cyber Defence, and GRC teams
  • You communicate clearly with both technical and non-technical stakeholders, focusing on practical risk reduction rather than theoretical security perfection
  • You have a pragmatic mindset and know how to balance speed, security, engineering quality, and business impact
What We Offer

On is a place that is centered around growth and progress. We offer an environment designed to give people the tools to develop holistically – to stay active, to learn, explore and innovate. Our distinctive approach combines a supportive, team-oriented atmosphere, with access to personal self-care for both physical and mental well-being, so each person is led by purpose.

On is an Equal Opportunity Employer. We are committed to creating a work environment that is fair and inclusive, where all decisions related to recruitment, advancement, and retention are free of discrimination.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Lead - Platform Security Engineer
Lead - Platform Security Engineer

On • Zürich

Vor Ort
CHF 140.000 - 180.000
Platform Security Lead: Secure-by-Design & Safe Pipelines
Platform Security Lead: Secure-by-Design & Safe Pipelines

On • Zürich

Vor Ort
CHF 140.000 - 180.000
Staff Platform Security Engineer - Build Secure DevOps
Staff Platform Security Engineer - Build Secure DevOps

On • Zürich

Vor Ort
CHF 180.000 - 270.000
Senior Product Security Engineer
Senior Product Security Engineer

Jobtailor • Zug

Vor Ort
CHF 100.000 - 130.000
Flexible vacation
Mental Health Days
Tuition reimbursement
+1
Senior IT Security Engineer
Senior IT Security Engineer

AO Foundation • Davos

Hybrid
CHF 120.000 - 190.000
Flexible hours
Flexible location
Social benefits
+3
Senior IT Security Engineer (ID2140)
Senior IT Security Engineer (ID2140)

AO Foundation • Davos

Hybrid
CHF 120.000 - 160.000
Flexible hours
Global team
Modern infrastructure
+2
Senior IT Security Engineer (ID2140)
Senior IT Security Engineer (ID2140)

AO Foundation • Schweiz

Hybrid
CHF 120.000 - 160.000
Flexible hours
Hybrid work
Pension and vacation benefits
+1
Security Engineer (gn) Microsoft Modern Workplace
Security Engineer (gn) Microsoft Modern Workplace

SoftwareOne • Tolochenaz

Hybrid
CHF 140.000 - 180.000
Mentor support
Flexible work
VP, Platform Engineering
VP, Platform Engineering

Frontify • Sankt Gallen

Hybrid
CHF 150.000 - 200.000
Senior Site Reliability Engineer (SRE) New Lausanne, Switzerland (Hybrid)
Senior Site Reliability Engineer (SRE) New Lausanne, Switzerland (Hybrid)

SpotMe • Lausanne

Hybrid
CHF 140.000 - 210.000