Staff / Principal Software Engineer, Infrastructure Security
Leads infrastructure security strategy and implementation across cloud, identity, runtime, and software supply chains. The role requires 8+ years of infrastructure or cloud security experience, staff/principal-level leadership, and hands-on expertise with major cloud and security platforms.
About the job
Responsibilities
- Set the technical direction for cloud, identity, and build/runtime security.
- Design and ship guardrails for workload identity, least-privilege IAM, network segmentation, secrets management, and production access.
- Harden the software supply chain end to end, from developer laptops to production deployments.
- Partner with Platform, SRE, and the Apps Platform team to make secure paths easy to use.
- Mentor engineers across the company and raise the security bar by default.
Requirements
- 8+ years of experience in infrastructure or cloud security, including at least 3 years at staff or principal level.
- Deep expertise in GCP, AWS, and Cloudflare security primitives, including IAM, networking, KMS, workload identity, and edge security.
- Hands-on experience with Kubernetes, Terraform, Wiz, GitHub Actions, and modern CI/CD.
- Knowledge of supply-chain security, including SLSA, Sigstore, and SBOMs.
- Comfort writing Go, Python, or Rust to ship security guardrails as code.
- Track record of measurably reducing blast radius involving secrets, lateral movement, and production access.
Nice to Have
- Experience securing multi-tenant platforms.
- Experience securing LLM- or agent-driven infrastructure.
Technology Stack
- Frontend: React, TypeScript
- Backend: Golang, Rust
- Cloud: Cloudflare, GCP, AWS, multiple LLM providers
- DevOps and tooling: GitHub Actions, Grafana, OTEL, Terraform
- Data: ClickHouse, Firestore, Spanner, BigQuery
Skills
GCP, AWS, Cloudflare, IAM, Kms, Kubernetes, Terraform, Wiz, GitHub Actions, Slsa, Sigstore, Sboms, Go, Python, Rust
Similar jobs
Security Engineering jobsLeads detection engineering and incident response across corporate, production, and AI-agent environments. The role requires 8+ years of relevant experience, strong detections-as-code expertise, cloud and telemetry knowledge, and proven leadership of high-severity security incidents.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Owns corporate security across identities, endpoints, SaaS, email, and workplace AI tools. The role requires 5+ years of corporate, enterprise, or endpoint security experience, strong IAM and MDM expertise, coding ability, and practical risk-based security judgment.