Staff Platform Security Engineer (Security)

Jobgether

United States

Remote

USD 200,000 - 250,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Equity participation
Performance bonus
Medical Insurance
Remote stipend for setup
Flexible hours
Fully remote work environment
Unlimited vacation
401(k) plan
Wellness benefit
Meal benefit
Global off-sites

Job summary

Jobgether is seeking a Staff Platform Security Engineer to own security across AWS and Kubernetes infrastructure, supporting products used by millions of people. You will write code, build controls, respond to incidents, and drive remediation in a remote environment.

You will lead security architecture, implement least-privilege models, Harden CI/CD and software supply chains, and partner with cross‑functional teams to embed security without slowing delivery.

Qualifications

  • 7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or related engineering discipline.
  • Deep hands-on experience securing production AWS environments, including IAM and resource policies, workload identity, network security, secrets management, logging, organization-level controls, and common cloud security failure modes.
  • Strong production Kubernetes security experience, preferably with Amazon EKS, including RBAC, workload identity, admission policies, network policies, pod security, secrets, and cluster hardening.
  • Experience securing mission-critical systems where compromise, excessive privilege, or loss of availability could have significant customer or business consequences.
  • Strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction across both human and machine access.
  • Experience securing CI/CD pipelines and software supply chains, including GitHub Actions or comparable systems, build runners, workload federation, artifacts, and production deployment paths.
  • Experience writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar technologies.
  • Ability to write production-quality code and automation using a language such as TypeScript, Python, Go, or Rust.

Responsibilities

  • Own and continuously improve security across a multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails.
  • Secure production Kubernetes environments running on Amazon EKS, covering cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation.
  • Design and implement least-privilege access models for engineers, services, and automation, including scoped, auditable, and time-bound access to sensitive production systems.
  • Protect mission-critical infrastructure supporting systems that process sensitive information and high-value operations.
  • Lead security architecture and design for new infrastructure, platform services, and major architectural changes.
  • Build reusable infrastructure and policy-as-code controls using technologies such as Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation.
  • Harden CI/CD and software supply chains, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and production access.
  • Develop security automation that identifies and remediates cloud and Kubernetes risks at scale, using AI-assisted workflows where they can materially improve analysis, coverage, or response speed.
  • Partner closely with Infrastructure, SRE, Developer Experience, and product engineering teams to establish practical platform security standards and drive adoption.
  • Take ownership of security issues from initial investigation through implementation, remediation, and production verification.
  • Contribute directly to incident response and security improvements while maintaining a balance between strong controls and engineering velocity.

Skills

Platform security
AWS security
Kubernetes security
IaC - Pulumi/Terraform
Programming: TS/Python/Go/Rust
Incident response
Security architecture
CI/CD security
GitHub Actions

Tools

Pulumi
Terraform
GitHub Actions
Kubernetes policy engines

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Platform Security Engineer (Security) based in United States.

As a Staff Platform Security Engineer, you will own security across critical AWS and Kubernetes infrastructure supporting products used by millions of people. You will work hands-on across cloud security, identity and access, workload isolation, CI/CD, software supply chains, and production systems. The role combines security architecture with practical engineering, requiring you to write code, build infrastructure controls, respond to incidents, and drive verified remediation. You will partner closely with infrastructure, SRE, developer experience, and product engineering teams to embed security into the platform without slowing delivery. You will also help shape an AI-native security function that uses automation and AI-assisted workflows to increase security coverage and response speed. This is a high-impact opportunity to influence architecture and strengthen the security of mission‑critical systems in a fully remote environment.

Accountabilities
  • Own and continuously improve security across a multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization‑level guardrails.
  • Secure production Kubernetes environments running on Amazon EKS, covering cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation.
  • Design and implement least-privilege access models for engineers, services, and automation, including scoped, auditable, and time-bound access to sensitive production systems.
  • Protect mission‑critical infrastructure supporting systems that process sensitive information and high‑value operations.
  • Lead security architecture and design for new infrastructure, platform services, and major architectural changes.
  • Build reusable infrastructure and policy-as-code controls using technologies such as Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation.
  • Harden CI/CD and software supply chains, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and production access.
  • Develop security automation that identifies and remediates cloud and Kubernetes risks at scale, using AI-assisted workflows where they can materially improve analysis, coverage, or response speed.
  • Partner closely with Infrastructure, SRE, Developer Experience, and product engineering teams to establish practical platform security standards and drive adoption.
  • Take ownership of security issues from initial investigation through implementation, remediation, and production verification.
  • Contribute directly to incident response and security improvements while maintaining a balance between strong controls and engineering velocity.
Requirements
  • 7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering discipline.
  • Deep hands‑on experience securing production AWS environments, including IAM and resource policies, workload identity, network security, secrets management, logging, organization‑level controls, and common cloud security failure modes.
  • Strong production Kubernetes security experience, preferably with Amazon EKS, including RBAC, workload identity, admission policies, network policies, pod security, secrets, and cluster hardening.
  • Experience securing mission‑critical systems where compromise, excessive privilege, or loss of availability could have significant customer or business consequences.
  • Strong understanding of identity, authorization, least privilege, isolation, and blast‑radius reduction across both human and machine access.
  • Experience securing CI/CD pipelines and software supply chains, including GitHub Actions or comparable systems, build runners, workload federation, artifacts, and production deployment paths.
  • Experience writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar technologies.
  • Ability to write production‑quality code and automation using a language such as TypeScript, Python, Go, or Rust.
  • High degree of ownership and agency, with the ability to take ambiguous platform security problems from investigation through implementation and verified remediation.
  • Strong communication skills and a proven ability to collaborate effectively with infrastructure and engineering teams while maintaining a high security standard.
  • Experience with AWS Nitro Enclaves or other trusted execution environments is an advantage.
  • Background securing financial, payments, wallet, custody, or other high‑value transaction systems is a plus.
  • Familiarity with AWS KMS, CloudHSM, cryptographic signing systems, key‑management infrastructure, or secrets‑management platforms is beneficial.
  • Experience operating or securing multi‑region AWS and Kubernetes environments at significant scale is a plus.
  • Familiarity with Istio, PrivateLink, Transit Gateway, eBPF‑based controls, or other cloud‑native networking technologies is advantageous.
  • Experience with GitHub OIDC, Argo CD, Helm, Crossplane, or Kubernetes‑based infrastructure delivery is beneficial.
  • Familiarity with security and observability platforms such as Wiz, Datadog, GuardDuty, Security Hub, or CloudTrail is a plus.
  • Experience building policy‑as‑code, automated remediation, or security tooling used across large engineering organizations is valuable.
  • Familiarity with blockchain infrastructure or self‑custodial wallet architecture is an advantage.
Benefits
  • $200,000–$250,000 USD target base salary, with final compensation influenced by skills, relevant experience, interview performance, and market factors such as location.
  • Equity participation.
  • Eligibility for a performance bonus program.
  • Comprehensive medical, dental, and vision insurance with 100% coverage.
  • Stipend for an ideal remote‑work setup.
  • Flexible working hours.
  • Fully remote and supportive work environment.
  • Unlimited vacation.
  • 401(k) retirement plan.
  • Monthly wellness benefit.
  • Weekly meal benefit.
  • Global company off‑sites.
  • Opportunity to secure AWS and Kubernetes infrastructure supporting products used by millions of people.
  • High‑impact work spanning cloud identity, production access, workload isolation, software supply chains, and mission‑critical infrastructure.
  • Opportunity to build security controls directly into the platform rather than operating solely in an advisory or review capacity.
  • Ability to influence architecture early and own security improvements through implementation and production verification.
  • Opportunity to contribute to an AI‑native security team focused on engineering, automation, and scalable security operations.
Data Privacy Notice

By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre‑contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

We appreciate your interest and wish you the best!

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Platform Security Engineer
Staff Platform Security Engineer

Colossus Technologies Group • United States

On-site
USD 140,000 - 230,000
Bonus
Equity
Competitive base salary
Senior Security Engineer
Senior Security Engineer

Activecampaign • United States

On-site
USD 126,000 - 154,000
HDHP + telehealth
Calm subscription
LinkedIn Learning
+3
Senior Manager, Engineering - Platform Security
Senior Manager, Engineering - Platform Security

United States Digital Space LLC • Los Angeles (CA)

Hybrid
USD 228,000 - 274,000
Security Engineer, Infrastructure
Security Engineer, Infrastructure

United States Digital Space LLC • New York (NY), Washington

On-site
USD 238,000 - 297,000
Health, dental & vision coverage
Retirement benefits
Learning stipend
+2
Senior Security Engineer – Hybrid (4649)
Senior Security Engineer – Hybrid (4649)

Hireclout • Los Angeles (CA)

On-site
USD 180,000 - 200,000
Competitive compensation package
Equity participation
100% covered medical, dental, and vision coverage
+5
Staff Security Engineer, Cloud Security
Staff Security Engineer, Cloud Security

United States Digital Space LLC • United States

On-site
USD 179,000 - 264,000
Health & wellness
Equity
Manager, Security Engineering, Cloud & AppSec
Manager, Security Engineering, Cloud & AppSec

Horizon3 • United States

Hybrid
USD 150,000 - 185,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2
Security Engineer, Infrastructure
Security Engineer, Infrastructure

Scale AI • Washington

On-site
USD 238,000 - 297,000
Health, dental & vision coverage
Retirement benefits
Learning & development stipend
+2
Manager, Security Engineering, Cloud & AppSec
Manager, Security Engineering, Cloud & AppSec

Horizon3 AI • United States

On-site
USD 149,000 - 185,000
Health, vision & dental insurance
Flexible vacation policy
Generous parental leave
+2
Contract- DevSecOps Engineer
Contract- DevSecOps Engineer

GSFSGroup • Houston (TX)

On-site
USD 120,000 - 150,000