Platform Security Engineer securing Phantom’s crypto-finance products across AWS and Kubernetes. Building cloud controls, identity protections, supply-chain security, and automated remediation.
Responsibilities
Own and improve security across Phantom’s multi-account AWS environment, including IAM, Identity Center, networking, compute, storage, secrets, logging, and organization-level guardrails
Secure production Kubernetes environments running on Amazon EKS, including cluster configuration, workload identity, RBAC, admission controls, network boundaries, secrets, container security, and tenant isolation
Design least-privilege access models for engineers, services, and automation
Build scoped, auditable, and time-bound access paths for sensitive production systems
Protect infrastructure supporting products and services that handle sensitive data and high-value operations
Lead security design for new infrastructure, platform services, and major architectural changes
Build reusable security controls using Pulumi, Terraform, Kubernetes policy engines, and automated configuration validation
Harden CI/CD and release systems, including GitHub Actions, workload federation, build runners, dependencies, artifacts, signing, provenance, and access to production environments
Build tools that identify and remediate cloud and Kubernetes risks at scale
Apply AI-assisted workflows where they improve analysis, coverage, or response speed
Partner with Infrastructure, SRE, Developer Experience, and product engineering teams
Establish platform-security standards and help teams adopt them
Requirements
7+ years of experience in platform security, cloud security, infrastructure security, security engineering, or a closely related engineering role
Deep, hands-on experience securing production AWS environments
Understanding of IAM and resource policies, workload identity, network security, secrets management, logging, and organization-level controls
Deep experience securing Kubernetes in production, preferably Amazon EKS
Experience with RBAC, workload identity, admission policy, network policy, pod security, secrets, and cluster hardening
Experience designing or securing mission-critical systems
Strong understanding of identity, authorization, least privilege, isolation, and blast-radius reduction
Experience securing CI/CD and software supply chains, including GitHub Actions or similar systems, build runners, workload federation, artifacts, and production deployment paths
Experience writing and reviewing infrastructure as code using Pulumi, Terraform, CloudFormation, or similar tools
Ability to write production-quality code or automation in TypeScript, Python, Go, or Rust
High agency and ownership
Clear communication and a strong track record of partnering with infrastructure and engineering teams
Candidates must be based in the US or Canada
Benefits
Equity
Eligibility to participate in the company’s performance bonus program
Comprehensive medical, dental, and vision insurance with 100% coverage
Stipend for your ideal remote setup
Flexible hours and a supportive remote environment
Senior AI Platform Developer building scalable AI services and LLM workflows for MaintainX’s industrial work execution platform. Improving reliability, observability, performance, and cost efficiency.
Infrastructure team lead building and operating Spare’s GCP and Kubernetes platform for on - demand transit. Leading developers while improving reliability, security, AI SRE, and cloud cost efficiency.
Senior AI Platform Developer building reusable, secure AI - agent infrastructure for Petal, a Canadian healthcare orchestration and billing company. Driving Azure - based platform capabilities across orchestration, evaluation, observability, and governance.
AI Platform Developer building Azure - based agent infrastructure for Petal, a Canadian healthcare orchestration and billing company. Creating secure, observable, governed AI services for product teams.
Kubernetes/DevOps Engineer operating Kubernetes infrastructure for a petabyte - scale social media platform. Building distributed systems and machine - learning workloads for Capgemini Engineering’s client.
Lead AI Platform Engineer securing and operating EQ Bank’s enterprise AI platforms. Driving Azure engineering, observability, automation, governance, and production readiness.
Senior Platform Engineer building and operating GitLab Orbit, a Rust - based knowledge graph service for GitLab’s DevSecOps platform. Improving distributed - system reliability, observability, cloud infrastructure, and data workflows.
Platform Software Engineer supporting Invoice Simple, EverCommerce’s invoicing SaaS for small businesses. Building cloud infrastructure, CI/CD pipelines, and reliable production systems.
Software Engineer building cloud infrastructure and deployment systems for Invoice Simple, EverCommerce’s invoicing platform for small businesses. Improving reliability, observability, and production operations.
Senior cybersecurity engineer securing L3Harris’s mission - critical platform - management systems for military and cruise ships. Hardening Linux, networks, software, and infrastructure across the product lifecycle.