
Staff Platform Security Engineer
Posted Sep 10

Posted Sep 10
This is a fully remote position, open to applicants in Philippines.
• Take charge of enhancing security across Azure, AKS, Azure SQL, networking, storage, identity, secrets, and production environments.
• Strengthen Kubernetes workloads, containers, ingress, workload identity, secrets, and network controls.
• Design and refine least-privilege and privileged access models, including RBAC, PIM, just-in-time access, MFA, and access reviews.
• Manage vulnerability processes, including triage, risk-based prioritization, remediation tracking, exceptions, and reporting.
• Configure and enhance security and monitoring tools to elevate threat detection and minimize unnecessary security alerts.
• Implement security guardrails across CI/CD and Infrastructure as Code, encompassing SAST, SCA, secrets scanning, IaC scanning, and container scanning.
• Collaborate with software engineers to ensure security findings are clear, actionable, and addressed at the source.
• Assist in security architecture reviews, threat modeling, incident response, and root-cause analysis as required.
• Collaborate with Security & Privacy Compliance on audits, risk assessments, customer reviews, and technical security evidence.
• Formulate security recommendations, standards, and implementation plans, clearly communicating them to both technical and executive stakeholders.
• Oversee platform security from strategy through execution, translating security requirements into practical controls.
• 8+ years of experience in cloud security, platform security, security engineering, infrastructure security, DevSecOps, SRE, DevOps, or similar technical infrastructure roles.
• 4+ years of security-focused experience in cloud security, platform security, application security, DevSecOps, or production security engineering.
• Extensive hands-on experience with Microsoft Azure, specifically AKS, Entra ID, networking, storage, Azure SQL, Key Vault/secrets management, monitoring, and production access controls.
• Strong knowledge of cloud and platform security architecture, least privilege, secure configuration, production access, and vulnerability remediation.
• Practical experience with Kubernetes and container security, including workload identity, ingress, network controls, secrets, and runtime hardening.
• Familiarity with IAM, RBAC, PIM, privileged access, just-in-time access, and access reviews.
• Solid Infrastructure as Code experience using Terraform, Bicep, ARM, or similar tools.
• Hands-on experience with CI/CD pipelines and software delivery workflows, including security controls and automated scanning.
• Strong ability to evaluate vulnerabilities based on exploitability, exposure, business impact, and blast radius, rather than relying solely on severity scores.
• Excellent communication skills, with the capability to work independently, identify security gaps, provide recommendations, and drive solutions to completion.
• Experience in regulated environments such as HIPAA, SOC 2, ISO 13485, ISO 27001, FDA-regulated software, healthcare SaaS, fintech, or other high-assurance environments.
• Familiarity with SaMD, medical device software, FDA QMSR, ISO 13485/MDSAP, or validated software development environments.
• Knowledge of tools such as Aikido, CrowdStrike, Vanta, New Relic, Microsoft Defender for Cloud, Microsoft Sentinel, or comparable solutions.
• Experience with SAML, OIDC, SCIM, SSO, MFA, Conditional Access, and PIM.
• Proficiency in Azure Policy, Log Analytics, Key Vault, managed identities, and workload identity.
• Familiarity with GitHub Actions, Azure DevOps, or similar CI/CD platforms.
• Experience with threat modeling, secure architecture reviews, incident response, or root-cause analysis.
• Relevant certifications such as Azure Security Engineer Associate, Certified Kubernetes Security Specialist (CKS), CCSP, CISSP, or equivalent practical experience.
• Experience with .NET, Angular, or multi-tenant SaaS environments.
• 100% remote work setup.
• Work from anywhere in the Philippines.
• Direct visibility and collaboration with the CTO.
• High-impact role with substantial technical ownership and autonomy.
• Opportunity to work on a cloud-native healthcare/SaMD platform.
• Exposure to modern Azure, AKS, Kubernetes, and cloud security technologies.
• Opportunity to operate in a regulated, high-assurance environment.
• Collaboration with Engineering, Product, IT, Quality, and Compliance teams.
OPENDataJobs
Presidio
EasyLlama - HR & Compliance Training For Modern Teams
Coinbase
Get handpicked remote jobs straight to your inbox weekly.