Skip to content
Shield AIShield AI

Senior Staff Cybersecurity Engineer, Platform Security

Senior technical owner building secure-by-default infrastructure, IaC modules, policy-as-code guardrails, and CI/CD security tooling for cloud and platform engineering teams.

About the job

What you'll do

  • Build the secure defaults: Infrastructure-as-Code modules, CI/CD pipeline templates, internal libraries, and golden-path scaffolding that make the secure choice the easy choice.
  • Engineer guardrails as code — policy-as-code (OPA/Conftest), admission controllers, cloud guardrails (SCPs / org policy), and pre-commit and CI checks — so the insecure path is blocked or flagged automatically.
  • Own the platform security tooling that other teams consume, so they don't have to build their own; replace recurring manual work with durable, self-service mechanisms.
  • Embed security into the software and infrastructure supply chain: pipeline security, build/artifact integrity, dependency and container scanning, and secrets management.
  • Engineer workload and service identity controls (least privilege, short-lived credentials, federated trust) so zero-standing-privilege is real and observable.
  • Write and maintain production-quality code and infrastructure that backs these controls.
  • Partner with platform, infrastructure, and product engineering teams early — review high-blast-radius designs against the internal Security Engineering standard while the design can still change, and turn recurring findings into a missing paved road, not just another fix.
  • Set technical direction and standards for secure-by-default; document them so they can be applied without us, and mentor and raise the bar for other engineers.

Required qualifications

  • Extensive experience in security engineering, platform/infrastructure engineering, DevSecOps, or a closely related field, with a track record of owning complex systems end-to-end.
  • Strong software engineering ability — you write, review, and ship production-quality code (any modern language) and treat infrastructure as software.
  • Hands-on experience building secure-by-default mechanisms: Infrastructure-as-Code, CI/CD pipeline security, and policy/guardrails as code.
  • Deep working knowledge of at least one major cloud provider and its security and identity model.
  • Demonstrated ability to design durable, automated solutions that reduce real risk without becoming a bottleneck — and to make explicit tradeoffs between security and the business.
  • Strong communication: you can explain a security concept to a product engineer in their language and to a leader in business terms, and you write recommendations people can act on.

Preferred qualifications

  • Strong DevSecOps background with hands-on Kubernetes (admission control, OPA/Gatekeeper, workload identity) and Terraform (reusable secure modules, policy-as-code).
  • Production coding experience in Go, Python, and/or Rust; comfortable with scripting/automation in Bash and PowerShell.
  • Depth in Azure security and identity (Entra ID, Azure Policy, Management Group guardrails).
  • Experience securing AI/ML systems, pipelines, or workloads.
  • Offensive security / red team experience, with the ability to think like an attacker and translate those findings into stronger defaults and guardrails.
  • Experience with supply-chain security (SLSA, sigstore/cosign, SBOMs), container/image hardening, and secrets management.
  • Experience operating security tooling as an internal product consumed self-service by other engineering teams.
  • Bachelor's degree or equivalent professional certification and experience.

Skills

Kubernetes, Terraform, Opa, Go, Python, Rust, Azure, Entra Id, AWS, GCP, CI/CD, Infrastructure As Code, Policy As Code, DevSecOps

Okta

Okta

Bellevue, WA
Staff Identity Governance and Access Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.

Okta

Okta

Bellevue, WA
Staff Identity Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.

Twilio

Twilio

United States

Staff Security Engineer
$156k+/yrRemote7+ YOESecurity Engineering

Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.

Twilio

Twilio

United States

Staff Enterprise Security Engineer, AI Security
$156k+/yrRemote7+ YOESecurity Engineering

Leads enterprise AI security architecture and develops security systems, automation, and agentic AI identity strategies at scale. Requires 7+ years in security or infrastructure security, enterprise technical leadership, cloud and container security expertise, and strong programming skills.

GitLab

GitLab

United States
Staff Security Researcher
$168k+/yrRemote7+ YOESecurity Engineering

Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.