Platform Security Engineer; Security
Listed on 2026-09-24
-
IT/Tech
Cybersecurity, AWS
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Platform Security Engineer (Security) based in United States.
As a Staff Platform Security Engineer, you will own security across critical AWS and Kubernetes infrastructure supporting products used by millions of people. You will work hands-on across cloud security, identity and access, workload isolation, CI/CD, software supply chains, and production systems. The role combines security architecture with practical engineering, requiring you to write code, build infrastructure controls, respond to incidents, and drive verified remediation.
You will partner closely with infrastructure, SRE, developer experience, and product engineering teams to embed security into the platform without slowing delivery. You will also help shape an AI-native security function that uses automation and AI-assisted workflows to increase security coverage and response speed. This is a high-impact opportunity to influence architecture and strengthen the security of mission‑critical systems in a fully remote environment.
- Own and continuously improve security across a multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization‑level guardrails.
- Secure production Kubernetes environments running on Amazon EKS, covering cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation.
- Design and implement least-privilege access models for engineers, services, and automation, including scoped, auditable, and time-bound access to sensitive production systems.
- Protect mission‑critical infrastructure supporting systems that process sensitive information and high‑value operations.
- Lead security architecture and design for new infrastructure, platform services, and major architectural changes.
- Build reusable infrastructure and policy-as-code controls using technologies such as Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation.
- Harden CI/CD and software supply chains, including Git Hub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and production access.
- Develop security automation that identifies and remediates cloud and Kubernetes risks at scale, using AI-assisted workflows where they can materially improve analysis, coverage, or response speed.
- Partner closely with Infrastructure, SRE, Developer Experience, and product engineering teams to establish practical platform security standards and drive adoption.
- Take ownership of security issues from initial investigation through implementation, remediation, and production verification.
- Contribute directly to incident response and security improvements while maintaining a balance between strong controls and engineering velocity.
- 7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering discipline.
- Deep hands‑on experience securing production AWS environments, including IAM and resource policies, workload identity, network security, secrets management, logging, organization‑level controls, and common cloud security failure modes.
- Strong production Kubernetes security experience, preferably with Amazon EKS, including RBAC, workload identity, admission policies, network policies, pod security, secrets, and cluster hardening.
- Experience securing mission‑critical systems where compromise, excessive privilege, or loss of availability could have significant customer or business consequences.
- Strong understanding of identity,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).