Staff Platform Security Engineer, Security

Posted 6 days ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Platform Security Engineer securing Phantom’s crypto-finance products across AWS and Kubernetes. Building cloud controls, identity protections, supply-chain security, and automated remediation.

Responsibilities

  • Own and improve security across Phantom’s multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails
  • Secure production Kubernetes environments running on Amazon EKS, including cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation
  • Design least-privilege access models for engineers, services, and automation
  • Build scoped, auditable, and time-bound access paths for sensitive production systems
  • Protect infrastructure supporting products and services that handle sensitive data and high-value operations
  • Lead security design for new infrastructure, platform services, and major architectural changes
  • Build reusable security controls using Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation
  • Harden CI/CD and release systems, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and access to production environments
  • Build tools that identify and remediate cloud and Kubernetes risks at scale
  • Apply AI-assisted workflows where they improve analysis, coverage, or response speed
  • Partner with Infrastructure, SRE, Developer Experience, and product engineering teams
  • Establish platform-security standards and help teams adopt them

Requirements

  • 7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering role
  • Deep, hands-on experience securing production AWS environments
  • Understanding of IAM and resource policies, workload identity, network security, secrets management, logging, and organization-level controls
  • Deep experience securing Kubernetes in production, preferably Amazon EKS
  • Experience with RBAC, workload identity, admission policy, network policy, pod security, secrets, and cluster hardening
  • Experience designing or securing mission-critical systems
  • Strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction
  • Experience securing CI/CD and software supply chains, including GitHub Actions or similar systems, build runners, workload federation, artifacts, and production deployment paths
  • Experience writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar tools
  • Ability to write production-quality code or automation in TypeScript, Python, Go, or Rust
  • High agency and ownership
  • Clear communication and a strong track record of partnering with infrastructure and engineering teams
  • Candidates must be based in the US or Canada

Benefits

  • Equity
  • Eligibility to participate in the company’s performance bonus program
  • Comprehensive medical, dental, and vision insurance with 100% coverage
  • Stipend for your ideal remote setup
  • Flexible hours and a supportive remote environment
  • Unlimited vacation—take time when you need it
  • 401(k) retirement plan
  • Monthly wellness benefit
  • Weekly meal benefit
  • Global off-sites

Job type

Full Time

Experience level

Lead

Salary

$200,000 - $250,000 per year

Degree requirement

No Education Requirement

Tech skills

AWSCloudKubernetesPythonRustTerraformTypeScriptGo

Location requirements

RemoteUnited States

Report this job

Found something wrong with the page? Please let us know by submitting a report below.