Platform Security Architect

Deel

España

On-site

EUR 90,000 - 150,000

Full time

19 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Stock grant opportunities
Flexible working office membership
Comprehensive health benefits

Job summary

Deel is seeking a Senior Platform Security Engineer to own security architecture across its cloud-native platform. You will lead security design, tooling, and enforcement throughout the SDLC, focusing on AWS IAM, container security, and supply chain integrity.

The role requires deep knowledge of cloud and application security, threat modeling, and experience steering cross-functional teams to reduce risk while enabling rapid product delivery.

Qualifications

  • 3+ years in cybersecurity with cloud and application security depth.
  • Deep AWS security expertise including IAM and data protection.
  • Experience with security platforms (Wiz, Snyk, Semgrep) and CI/CD integration.

Responsibilities

  • Define platform security architecture across applications, services, and cloud environments (AWS).
  • Operate cloud posture tooling and runtime security scanning, tying findings to actionable fixes.
  • Own IAM, least-privilege, and multi-tenant auth controls across layers.
  • Embed security into SDLC and CI/CD pipelines with clear build gates.
  • Secure containers and Kubernetes through image hardening and runtime protection.
  • Protect software supply chain and SBOMs from first npm install to runtime.
  • Lead threat modeling and risk-based remediation with engineering teams.
  • Run vulnerability management and incident response with cross-functional partners.
  • Collaborate with privacy/compliance to satisfy SOC 2 II, ISO 27001, PCI DSS, and GDPR.

Skills

Cloud security
Application security
CI/CD security
Threat modeling
Security architecture
English communication

Tools

Wiz
Aikido
Snyk
Semgrep
GitHub Advanced Security
HashiCorp Vault
Kubernetes security

Job description

Who We Are Is What We Do.

Deel is the all-in-one payroll and HR platform for global teams. Our vision is to unlock global opportunity for every person, team, and business. Built for the way the world works today, Deel combines HRIS, payroll, compliance, benefits, performance, and equipment management into one seamless platform. With AI-powered tools and a fully owned payroll infrastructure, Deel supports every worker type in 150+ countries—helping businesses scale smarter, faster, and more compliantly.

Who We Are Is What We Do.

Deel is the all-in-one payroll and HR platform for global teams. Our vision is to unlock global opportunity for every person, team, and business. Built for the way the world works today, Deel combines HRIS, payroll, compliance, benefits, performance, and equipment management into one seamless platform. With AI-powered tools and a fully owned payroll infrastructure, Deel supports every worker type in 150+ countries—helping businesses scale smarter, faster, and more compliantly.

Among the largest globally distributed companies in the world, our team of 7,000 spans more than 100 countries, speaks 74 languages, and brings a connected and dynamic culture that drives continuous learning and innovation for our customers.

Why should you be part of our success story?

As the fastest-growing Software as a Service (SaaS) company in history, Deel is transforming how global talent connects with world‑class companies – breaking down borders that have traditionally limited both hiring and career opportunities. We're not just building software; we're creating the infrastructure for the future of work, enabling a more diverse and inclusive global economy. In 2024 alone, we paid $11.2 billion to workers in nearly 100 currencies and provided healthcare and benefits to workers in 109 countries—ensuring people get paid and protected, no matter where they are.

Our momentum is reflected in our achievements and customer satisfaction: CNBC Disruptor 50, Forbes Cloud 100, Deloitte Fast 500, and repeated recognition on Y Combinator's top companies list – all while maintaining a 4.83 average rating from 15,000 reviews across G2, Trustpilot, Captera, Apple and Google.

Your experience at Deel will be a career accelerator. At the forefront of the global work revolution, you'll tackle complex challenges that impact millions of people's working lives. With our momentum—backed by a $17.3 billion valuation and $1 B in Annual Recurring Revenue (ARR) in just over five years—you'll drive meaningful impact while building expertise that makes you a sought‑after leader in the transformation of global work.

Responsibilities
  • Own the platform security architecture strategy across Deel's applications, services, and cloud environments, with a primary focus on AWS. Define secure design patterns, reference architectures, guardrails, and baseline configurations that teams build against by default.
  • Run Deel's security tooling as one program. Operate and tune Wiz for cloud posture (CSPM) and runtime visibility, and Aikido for SAST, SCA, secrets detection, container, IaC, and DAST scanning. Connect findings across code and cloud so the team fixes what is actually exploitable, not what is merely noisy.
  • Design identity and access at every layer. Own least‑privilege cloud IAM (cross‑account roles, permission boundaries, SCPs, just‑in‑time access) and application authentication and authorization (session and token handling, multi‑tenant isolation, object‑level access control).
  • Embed security into the SDLC and CI/CD pipelines. Build the guardrails for application code and Infrastructure as Code alike, with a clear model for what blocks a build and what warns.
  • Secure containers and Kubernetes. Set the standards for image hardening and signing, admission control, pod security, network policies, secrets management, and runtime protection.
  • Own software supply chain security. Cover dependency and transitive risk, malicious package detection, SBOMs, build integrity, and artifact provenance, from the first npm install to the running workload.
  • Lead threat modeling for new and existing systems, and make it part of how engineering designs software rather than a security‑team ritual.
  • Run vulnerability management for findings from scanners, pentests, and bug bounty: triage, exploitability assessment, SLAs, remediation partnership with engineering, and reporting on risk reduction over time.
  • Lead platform security incident response across application and cloud layers: triage, containment, forensics, root cause analysis, and post‑incident hardening.
  • Partner with Privacy/Compliance so platform controls satisfy SOC 2 Type II, ISO 27001, PCI DSS, and GDPR, and design decisions stay defensible and auditable.
  • Scale security through people. Build a Security Champions program and secure coding enablement so security knowledge spreads across engineering instead of pooling in the security team.
  • Act as the technical authority on platform security, reviewing high‑risk designs, evaluating vendors, and influencing engineering and cloud strategy at the leadership level.
  • Use Artificial Intelligence as an enabler to find new insights, learn from past mistakes, and continuously improve Deel's security posture, including securing the AI features Deel ships.
Qualifications
  • 3+ years of hands‑on experience in cybersecurity, with real depth in both cloud security and application security engineering or architecture.
  • Deep AWS security expertise: IAM design, network controls, logging and monitoring (CloudTrail, Security Hub, GuardDuty), and data protection.
  • Deep application security expertise: OWASP Top 10 and API Security Top 10, authentication and authorization design, injection and deserialization, SSRF, business logic flaws, and secure session handling.
  • Proven hands‑on experience operating security platforms such as Wiz (or Orca, Prisma Cloud) and Aikido (or Snyk, Semgrep, GitHub Advanced Security), including rollout, tuning, false‑positive reduction, and integration with engineering workflows.
  • Strong experience building security gates into CI/CD pipelines for both application code and Infrastructure as Code.
  • Strong experience securing containers and Kubernetes: image hardening, runtime security, pod security standards, and Kubernetes RBAC.
  • Hands‑on threat modeling experience (STRIDE, attack trees, or equivalent) applied to real systems, with findings turned into concrete engineering work.
  • Ability to read, reason about, and write production code in at least one modern language (TypeScript/Node.js, Python, Go, or Java).
  • Experience with secrets management (HashiCorp Vault, AWS Secrets Manager) and encryption patterns for data at rest and in transit.
  • Experience running vulnerability management or a bug bounty/pentest program, and driving remediation across teams you don't manage.
  • Strong working knowledge of SOC 2 Type II, ISO 27001, PCI DSS, and GDPR.
  • Ability to turn complex security concepts into clear guidance for engineers and risk‑based recommendations for executives.
  • Excellent English, written and verbal.
Advantageous Experience
  • Background in software engineering, DevSecOps, or platform engineering before moving into security. Credibility with engineers and the ability to ship fixes, not just file tickets.
  • Offensive security background (web/API or cloud penetration testing, exploit development, CTFs) used to inform defensive design.
  • Experience securing multi‑tenant SaaS at scale, including tenant isolation and EU data residency requirements.
  • Experience securing AI/LLM‑powered features (prompt injection, agent and tool abuse, data leakage) or applying AI to security workflows such as triage and automated remediation.
  • Multi‑cloud experience (GCP or Azure alongside AWS).
  • Familiarity with eBPF‑based runtime tooling (Wiz, Cilium, Falco, or similar).
  • Experience building a Security Champions program or secure coding curriculum.
  • Experience in high‑growth fintech or global HR technology with complex regulatory requirements.
  • Open‑source contributions, CVE credits, published research, or conference talks (OWASP Global AppSec, fwd:cloudsec, re:Inforce, BSides, Black Hat, DEF CON).
  • Relevant certifications: AWS Certified Security Specialty, OSWE, OSCP, GWAPT, CSSLP, CCSP, or CISSP.
Total Rewards

Our workforce deserves fair and competitive pay that meets them where they are. With scalable benefits, rewards, and perks, our total rewards programs reflect our commitment to inclusivity and access for all.

  • Our salary range reflects gross base salary. For commercial roles with commission eligibility, this figure represents On‑Target Earnings (OTE), inclusive of base salary and target commission.
  • Salary ranges are quoted in USD as a consistent global reference. Your offer will be localized to your country's currency using a market‑aligned conversion.
  • Final pay is based on objective, job‑related criteria including experience, skills, and location.
  • We don't ask about salary history. Offers are based on the role and what you bring to it.
Some things you'll enjoy
  • Stock grant opportunities dependent on your role, employment status and location
  • Additional perks and benefits based on your employment status and country
  • Optional flexible working office membership, with IWG

At Deel, we're an equal‑opportunity employer that values diversity and positively encourage applications from suitably qualified and eligible candidates regardless of race, religion, sex, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, pregnancy or maternity or other applicable legally protected characteristics.

Unless otherwise agreed, we will communicate with job applicants using Deel‑specific emails, which include @deel.com and other acquired company emails like @payspace.com and @paygroup.com. You can view the most up‑to‑date job listings at Deel by visiting our careers page.

Deel welcomes persons with disabilities to apply to any of our open roles. We will provide application and/or interview accommodations on request throughout the recruitment, selection and assessment process for applicants with disabilities or other needs. If you require application and/or interview accommodations, please inform our Talent Acquisition Team via email (recruiting@deel.com) and a team member will be in touch to ensure your equal participation.

As part of our hiring process, we primarily rely on interviews and role‑related assessments. In limited cases, we may also consider informal background information relevant to the role, in line with our privacy and fairness obligations.

This application process may utilise Automated Employment Decision Tools (AEDT) and AI systems to assist in evaluating candidates based on experience level, technical skills and qualifications. This processing is conducted in compliance with applicable Data Protection, AI Governance and Labour Laws. We ensure human oversight is maintained in all final hiring decisions. Your personal data is not used to train AI models. For more information on how we process your personal data, please see our Recruitment Privacy Policy.

  • For NYC Residents: In accordance with NYC Local Law 144, an independent bias audit has been conducted on AEDT.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Product Manager II - Platform
Senior Product Manager II - Platform

Deel • Spain

Hybrid
EUR 98,000 - 134,000
Stock grant opportunities
Flexible working office membership
AI Security Specialist
AI Security Specialist

Deel • Spain

On-site
EUR 103,000 - 154,000
Flexible working office membership
Competitive total rewards
Solutions Engineer, Deel HR
Solutions Engineer, Deel HR

Deel • Spain

On-site
EUR 65,000 - 95,000
Stock grants
Flexible office membership
Additional perks
Senior Product Manager II - Tax Filling
Senior Product Manager II - Tax Filling

Deel • Spain

Remote
EUR 80,000 - 116,000
Stock grant opportunities
Flexible office membership
Senior Product Manager II
Senior Product Manager II

Deel • Spain

Hybrid
EUR 70,000 - 110,000
Stock grant opportunities
Flexible office membership
Account Executive, Mobility, SMB & Mid-Market
Account Executive, Mobility, SMB & Mid-Market

Deel • Spain

Hybrid
EUR 40,000 - 70,000
Stock grant opportunities
Flexible office membership
Additional perks and benefits
Product Operations Manager
Product Operations Manager

Deel • Spain

Hybrid
EUR 60,000 - 90,000
Stock grants
Flexible office membership
Additional perks
Operations Manager | Payroll Solutions
Operations Manager | Payroll Solutions

Deel • Spain

Hybrid
EUR 107,000 - 161,000
Stock grants
Additional perks
Flexible office membership
Senior Product Manager II — Brain GTM
Senior Product Manager II — Brain GTM

Deel • Spain

Hybrid
EUR 70,000 - 100,000
Stock grants
Flexible working
Office membership
Systems Integration Manager | EMEA
Systems Integration Manager | EMEA

Deel • Spain

Hybrid
EUR 65,000 - 90,000
Stock grants
Flexible office membership
Additional perks