Senior Platform Security Engineer
Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.
About the job
Responsibilities
- Own end-to-end software engineering projects on an autonomous, horizontally integrated platform security team.
- Define identity management for autonomous agents and other non-human actors, including provisioning, scoping, authentication, authorization, and auditing.
- Build and evolve an employee authorization platform with discoverable, role-based, least-privilege, and self-service permissions.
- Design and harden Zero Trust architecture for human and service-to-service authentication across internal tooling.
- Automate continuous permission right-sizing according to least-privilege principles.
- Develop secure cloud identity baselines and secure the software supply chain from development through CI/CD and production.
- Advise on risk assessments, architecture, threat modeling, and code reviews.
- Build service-to-service and agent-to-service authentication and authorization capabilities.
- Provision service identities using PKI and mutual TLS (mTLS).
- Improve infrastructure access tooling for short-lived, auditable access.
- Improve secrets issuance, rotation, and scoping across infrastructure.
Requirements
- 5+ years of experience building and operating production systems or infrastructure.
- 3+ years of experience writing software in a general-purpose programming language.
- 3+ years of experience securing systems with millions of users.
- Experience building or operating identity and access management systems, including authentication, authorization, or access control at scale.
- Understanding of RBAC, OAuth, OIDC, SSO, Zero Trust architectures, mTLS, and cloud IAM.
- Experience building and securing multi-cloud environments.
- Experience designing and building software for internal or external customers.
Nice-to-haves
- Experience with Kubernetes, Docker, Distroless, or OCI.
- Familiarity with Terraform, Bazel, or Buildkite.
- Experience managing workload identity with PKI and operating mTLS between services.
- Experience with Cloudflare Access or Teleport.
- Experience with Vault, cloud KMS, or secrets managers, including rotation and least-privilege access.
- Experience debugging distributed systems on GCP, Cloudflare, or AWS.
- Experience leading complex migrations or engineering-wide risk management programs.
- Experience operating a service mesh such as Envoy or Istio.
- Experience managing and securing Linux or bare-metal hosts, including Salt.
Compensation
- US base salary: $196,000–$245,000, plus equity and benefits.
Skills
Identity And Access Management, Python, TypeScript, Rust, RBAC, OAuth, OIDC, SSO, Zero Trust, Mtls, Cloud Iam, Kubernetes, Terraform, Pki, Secrets Management
Similar jobs
Security Engineering jobsBuild secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.
Own and advance the security of Anyscale’s production and multi-cloud infrastructure, including hardening, segmentation, Kubernetes runtime protection, and access controls. Requires 8+ years of security engineering experience and hands-on expertise with AWS, Azure, Kubernetes, and cloud security tooling.
Develops and operates detection engineering systems across endpoint, cloud, container, and SaaS environments. The role requires at least six years in detection, incident response, or offensive security, strong attacker TTP knowledge, macOS expertise, and detection-as-code experience.