Staff Platform Security Engineer (Security)
AWSKubernetesIAMTerraformPulumiPythonTypeScriptGoGitHub ActionsCloudFormation
About the Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Platform Security Engineer (Security) based in United States. This is a senior, hands-on platform security role focused on protecting critical cloud and infrastructure environments at scale. You will own security across AWS and Kubernetes, securing identities, workloads, control planes, deployment systems, and mission-critical infrastructure. The role combines deep technical execution with architectural influence, automation, incident response, and cross-functional leadership. You will work closely with Infrastructure, SRE, Developer Experience, and engineering teams to build practical controls that strengthen security without slowing product delivery. The environment is fully remote, highly engineering-driven, and designed for people who take ownership of complex security challenges from investigation through verified remediation. You will also help shape an AI-native security function by applying automation and AI-assisted workflows where they can meaningfully improve security coverage and response speed. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Platform Security Engineer (Security) based in United States. This is a senior, hands-on platform security role focused on protecting critical cloud and infrastructure environments at scale. You will own security across AWS and Kubernetes, securing identities, workloads, control planes, deployment systems, and mission-critical infrastructure. The role combines deep technical execution with architectural influence, automation, incident response, and cross-functional leadership. You will work closely with Infrastructure, SRE, Developer Experience, and engineering teams to build practical controls that strengthen security without slowing product delivery. The environment is fully remote, highly engineering-driven, and designed for people who take ownership of complex security challenges from investigation through verified remediation. You will also help shape an AI-native security function by applying automation and AI-assisted workflows where they can meaningfully improve security coverage and response speed. Accountabilities: Own and continuously improve security across a multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level security guardrails. Secure production Kubernetes environments running on Amazon EKS, covering cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation. Design least-privilege access models for engineers, services, and automation, while creating scoped, auditable, and time-bound access paths for sensitive production systems. Protect mission-critical infrastructure supporting products and services that process sensitive data and high-value operations, with a focus on reducing compromise risk, excessive privilege, and operational impact. Lead security architecture for new infrastructure, platform services, and major architectural changes, ensuring security requirements are incorporated early in the design process. Build reusable security controls through infrastructure and policy as code using technologies such as Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation. Strengthen CI/CD and software supply chain security across build, deployment, and release systems, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and production access. Develop security automation that identifies and remediates cloud and Kubernetes risks at scale, applying AI-assisted workflows when they can materially improve analysis, coverage, or response speed. Partner closely with Infrastructure, SRE, Developer Experience, and product engineering teams to establish practical platform-security standards and drive effective adoption across engineering. Requirements: Bring 7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering discipline. Have deep, hands-on experience securing production AWS environments, including IAM and resource policies, workload identity, network security, secrets management, logging, organization-level controls, and common cloud security failure modes. Demonstrate strong production Kubernetes security experience, preferably with Amazon EKS, including RBAC, workload identity, admission policies, network policies, pod security, secrets, and cluster hardening. Have experience designing or securing mission-critical systems where compromise, excessive privilege, or loss of availability could create significant customer or business impact. Possess a strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction across both human and machine access. Have experience securing CI/CD and software supply chains, including GitHub Actions or similar platforms, build runners, workload federation, artifacts, and production deployment paths. Be experienced in writing and reviewing infrastructure as code using tools such as Pulumi, Terraform, CloudFormation, or comparable technologies. Be able to write production-quality code or automation in a language such as TypeScript, Python, Go, or Rust. Demonstrate high agency and ownership, with the ability to take ambiguous platform-security problems from initial investigation through implementation and verified remediation. Communicate clearly and collaborate effectively with infrastructure and engineering teams while maintaining a high security standard and balancing practical delivery needs. Experience with AWS Nitro Enclaves or other trusted execution environments, financial or high-value transaction systems, key-management infrastructure, multi-region environments, service meshes, cloud-native networking, or blockchain infrastructure is advantageous. Familiarity with technologies such as AWS KMS, CloudHSM, GitHub OIDC, Argo CD, Helm, Crossplane, Istio, PrivateLink, Transit Gateway, eBPF-based controls, Wiz, Datadog, GuardDuty, Security Hub, or CloudTrail is a plus. Be legally authorized to work in the applicable job location and able to travel when required; the role does not provide visa sponsorship. Benefits: Competitive base salary ranging from $200,000 to $250,000 USD , plus equity and benefits, with final compensation influenced by skills, relevant experience, interview performance, market factors, and location. Eligibility to participate in a performance bonus program. Comprehensive medical, dental, and vision insurance with 100% coverage . Stipend to support an ideal remote work setup. Flexible working hours within a supportive fully remote environment. Unlimited vacation to support flexibility and time away when needed. 401(k) retirement plan. Monthly wellness benefit and weekly meal benefit. Opportunities to work on high-impact security challenges involving AWS, Kubernetes, cloud identity, production access, workload isolation, software supply chains, and mission-critical infrastructure. Global off-site opportunities and exposure to an engineering-focused, AI-native security environment. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
You'll be redirected to Jobgether's application page
Job Details
Salary
$200K–$250K
Location
United States
Job type
Full-time
Category
Security Engineering
Experience
7+ years
Posted
Today
Job Highlights
- $200K–$250K salary
- 7+ years level role
- 100% Remote — open to candidates in United States
About Jobgether
This job is hosted by Jobgether. Clicking Apply opens their site.
Remote Work Style
Mixed
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.