
Staff Platform Security Engineer, Security
Posted 13 hours ago

Posted 13 hours ago
This is a fully remote position, open to applicants in United States, +1 more country.
• Take ownership and enhance security across Phantom’s multi-account AWS infrastructure, involving IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails.
• Safeguard production Kubernetes environments operating on Amazon EKS, which includes cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation.
• Develop least-privilege access models tailored for engineers, services, and automation.
• Create scoped, auditable, and time-bound access paths for sensitive production systems.
• Shield infrastructure that underpins products and services handling sensitive data and high-stakes operations.
• Spearhead security design for new infrastructure, platform services, and significant architectural transformations.
• Construct reusable security controls utilizing Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation.
• Strengthen CI/CD and release systems, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and access to production environments.
• Develop tools that detect and remediate cloud and Kubernetes vulnerabilities at scale.
• Implement AI-assisted workflows to enhance analysis, coverage, or response speed.
• Collaborate with Infrastructure, SRE, Developer Experience, and product engineering teams.
• Establish platform-security standards and assist teams in their adoption.
• Over 7 years of experience in platform security, cloud security, infrastructure security, security engineering, or a related engineering role.
• Extensive, hands-on experience in securing production AWS environments.
• Proficient understanding of IAM and resource policies, workload identity, network security, secrets management, logging, and organization-level controls.
• Significant experience in securing Kubernetes in production, preferably on Amazon EKS.
• Familiarity with RBAC, workload identity, admission policy, network policy, pod security, secrets, and cluster hardening.
• Experience in designing or securing mission-critical systems.
• Strong grasp of identity, authorization, least privilege, isolation, and blast-radius reduction principles.
• Background in securing CI/CD and software supply chains, including GitHub Actions or similar systems, build runners, workload federation, artifacts, and production deployment pathways.
• Experience in writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar tools.
• Capability to write production-quality code or automation in TypeScript, Python, Go, or Rust.
• High level of agency and ownership.
• Effective communication and a proven track record of collaboration with infrastructure and engineering teams.
• Candidates must reside in the US or Canada.
• Equity.
• Eligibility to participate in the company’s performance bonus program.
• Comprehensive medical, dental, and vision insurance with 100% coverage.
• Stipend for your ideal remote setup.
• Flexible hours and a supportive remote working environment.
• Unlimited vacation—take time as needed.
• 401(k) retirement plan.
• Monthly wellness benefit.
• Weekly meal benefit.
• Global off-sites.
Helpware
Capgemini
Bitso
Peraton
Get handpicked remote jobs straight to your inbox weekly.