Senior Platform Engineer, Security
Founding Platform Engineer, Security building secure multi-tenant infrastructure, golden paths, and automation for Decagon's conversational AI platform. Requires 5+ years infrastructure experience, deep GCP/AWS knowledge, and strong IaC and coding skills.
About the job
Responsibilities
- Design and implement secure, multi-tenant infrastructure that isolates customer data while enabling efficient AI model serving across the platform
- Build "golden paths" for security including service templates, libraries, terraform policies, and automation so new services are secure and production-ready by default
- Own infrastructure-as-code (Terraform) and GitOps best practices, including reusable modules and policy-as-code
- Expand and help operate the platforms behind alerting detection, secrets management, IAM, and automated remediation, integrating them cleanly into CI/CD and developer workflows
- Partner with Security, Infrastructure, and product engineering teams to translate enterprise and compliance requirements (SOC 2, ISO 27001, GDPR) into reliable, automated technical controls
- Participate in security on-call and continuously raise the bar on operability, runbooks, and incident learnings
Requirements
- 5+ years building and operating production infrastructure, with meaningful exposure to security or a strong interest in moving deeper into security problems
- Deep knowledge of Google Cloud Platform and/or AWS, including compute, networking, IAM, and security services
- Proficiency with infrastructure-as-code (Terraform, Ansible, or similar) and a track record of building developer-facing tooling and automation
- Strong coding ability in at least one systems language (Python, Go, TypeScript) and comfort building paved-path tooling teams actually adopt
- Experience applying AI-assisted tooling (Cursor, Claude Code, and similar) to make engineers dramatically more effective
- Experience with secure container deployment, service mesh, and Kubernetes security best practices
- Observability and incident-response tooling experience (instrumentation, alerting, dashboards), with a bias toward eliminating toil
- Clear written communication and the ability to turn ambiguous requirements into simple, reliable designs
Nice-to-Haves
- Track record of being an early or founding platform/infrastructure/security engineer at another company
- Experience building internal platforms: service templates, paved-road deployment, self-serve environments, or developer portals
- Security-minded approach to the software supply chain (provenance, secrets, least privilege) and familiarity with static analysis tooling (Semgrep, CodeQL)
- Experience with detection and response data pipelines (Kafka/Pulsar, Splunk/Panther/RunReveal, or similar)
- Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR) from an infrastructure and platform perspective
Compensation & Benefits
- $200K – $330K + equity
- Take what you need vacation policy
- Medical, Dental, and Vision benefits
- Life Insurance and Disability Benefits
- Retirement Plan (e.g., 401K)
- Parental Leave
- Fertility and family building benefits through Carrot
- Daily lunches and snacks in the office
Skills
GCP, AWS, Terraform, Ansible, Python, Go, TypeScript, Kubernetes, IAM, SOC 2, ISO 27001, GDPR
Similar jobs
Security Engineering jobsBuild secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.
Own and advance the security of Anyscale’s production and multi-cloud infrastructure, including hardening, segmentation, Kubernetes runtime protection, and access controls. Requires 8+ years of security engineering experience and hands-on expertise with AWS, Azure, Kubernetes, and cloud security tooling.
Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.