Platform Security Engineer
Develop and maintain secure platform software spanning authentication, authorization, communications, data access, and automated security testing. The role requires 5+ years of security-focused software development experience, strong coding skills, and expertise in cloud and container security.
About the job
Responsibilities
- Design, develop, and maintain secure software for core platform functionality, including authentication and authorization systems, secure service-to-service communication, API security, secure data storage, and access controls.
- Collaborate with engineering and product teams to integrate security best practices throughout the software development lifecycle.
- Monitor emerging security threats, vulnerabilities, and mitigation strategies.
- Conduct security code reviews and identify risks in existing codebases.
- Develop and implement automated security testing procedures.
- Respond to security incidents and participate in incident response procedures.
- Identify and implement enhancements that continuously improve the platform’s security posture.
- Document security processes, procedures, and best practices.
- Build reliable, scalable, and well-tested components and take ownership of security tasks and features.
Requirements
- Bachelor’s degree in computer science or a related field.
- At least 5 years of software development experience with a strong focus on security.
- Experience designing and implementing secure authentication and authorization systems.
- In-depth knowledge of secure coding principles and practices, including the OWASP Top 10.
- Experience with secure communication protocols such as TLS/SSL.
- Familiarity with security testing tools and methodologies, including static code analysis and penetration testing.
- Strong coding skills in one or more of Go, Python, Java, or C++.
- Knowledge of cloud security principles and tools, such as AWS Security and Google Cloud Security.
- Knowledge of container security, including Docker Security and Kubernetes Security.
- Strong problem-solving, analytical, communication, and collaboration skills.
- Ability to work independently and in cross-functional teams.
Nice to Have
- Master’s degree in computer science or a related field.
- Interest in learning and owning varied aspects of security.
Compensation & Benefits
- Base salary range: $185,000–$260,000 annually.
- Potential eligibility for variable compensation, equity, and benefits.
- Medical, vision, and dental coverage.
- Generous paid time off.
- 401(k) plan.
- Home office improvement stipend.
- Annual education and wellness stipends.
- Company events and daily healthy lunches.
Skills
Authentication, Authorization, Api Security, Tls/Ssl, Owasp Top 10, Static Code Analysis, Penetration Testing, Go, Python, Java, C++, Aws Security, Google Cloud Security, Docker Security, Kubernetes Security
Similar jobs
Security Engineering jobsBuild and lead a Security Quality Management System for agentic and human-led SOC investigations, establishing quality standards, sampling, validation, reporting, and corrective actions. The role requires 5+ years in quality, governance, operational excellence, or controls, plus security operations and people-management experience.
Leads vulnerability management and application-security initiatives across the technology stack, securing operating-system images, open-source dependencies, CI/CD pipelines, containers, and cloud-native systems. Requires 5+ years of application-security experience, coding ability, and expertise in vulnerability-scanning practices.
Own and strengthen Onebrief’s corporate security stack across endpoints, identity, SaaS, Zero Trust, and monitoring. The role emphasizes security automation, configuration-baseline enforcement, telemetry integration, and continuously validated compliance controls.
The Security Engineer will secure cloud infrastructure, engineering systems, APIs, model-training environments, and GPU clusters while supporting rapid delivery. The role requires hands-on cloud security, IAM, secrets and certificate management, compliance ownership, vulnerability monitoring, and incident response experience.
Own and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.