Skip to content
DoxelDoxel

Senior Platform Engineer, Security

Build and secure Doxel's internal developer platform on GCP. Own cloud security posture, embed security into CI/CD pipelines, and drive adoption of secure golden paths across engineering teams.

About the job

What You'll Do

  • Work with DevOps team to build out golden paths that streamline developer and builder workflows streamlining and applying shift left security policies on CI/CD deployment, internal tooling, LLM, and data science workflows
  • Own cloud security posture on Google Cloud, landing-zone guardrails, least-privilege IAM, secrets and key management, codified as infrastructure-as-code so secure defaults are baked into golden paths rather than bolted on after
  • Continuously evaluate attack surfaces across the application, infrastructure, and cloud, prioritize findings by exploitability and blast radius, and feed the highest-leverage fixes back into the platform
  • Set and enforce AI-usage best practices, guardrails for agentic coding tools internally and Provide a security point of view on product AI/LLM features (prompt injection, data egress, model supply chain), in partnership with engineering leadership
  • Action on improving security and compliance through a risk based approach implementing SOC2, ISO27001, and ISO27701 security and compliance frameworks
  • Drive adoption and raise the security bar across engineering through better defaults, not mandates

What You Bring

  • 6+ years in platform engineering, infrastructure/DevOps, or site reliability, with real depth building infrastructure, not just operating it
  • Strong infrastructure-as-code skills (Terraform) and a track record of replacing ad hoc infra with reusable, self-service patterns
  • Hands-on cloud depth, ideally Google Cloud (AWS or Azure translates), including IAM, networking, and least-privilege design
  • Strong experience with Kubernetes and containerized workloads in production
  • Practical experience embedding security tooling into CI/CD (SAST, SCA, secret scanning, supply chain controls) and building secure-by-default pipelines
  • Strong programming or scripting ability (Python, Go, or similar) for building platform and automation tooling
  • A security mindset: you design for least privilege and think about how things get abused, even when security is not the headline of the task
  • Demonstrated ability to drive platform adoption and influence engineering teams without formal management authority

Preferred

  • Experience standing up an internal developer platform or paved-road program from scratch
  • Working knowledge of AI/LLM security risks and a point of view on using AI tools safely
  • SOC 2, ISO 27001, or similar compliance experience in a fast-moving company
  • Experience securing data warehouses or large data pipelines (Snowflake a plus)
  • Familiarity with construction tech, BIM/3D data, or other domain-rich data products

Skills

Terraform, GCP, Kubernetes, Python, Go, IAM, CI/CD, SAST, Sca, SOC 2, ISO 27001

Starburst

Starburst

Boston, MA

Senior Application Security Engineer
$175k+/yrOn-site5+ YOESecurity Engineering

Own and scale Starburst’s application and product security program through secure-by-default engineering, automated vulnerability management, threat modeling, and autonomous offensive testing. The role requires 5–7 years of security-focused experience, strong software supply chain expertise, and the ability to engage enterprise customers and lead engineers.

Jasper

Jasper

United States

Senior Security Engineer
$174k+/yrRemote8+ YOESecurity Engineering

The Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.

Jasper

Jasper

United States

Senior GRC Lead
$174k+/yrRemote8+ YOESecurity Engineering

Own and scale Jasper’s governance, risk, and compliance program for AI-native SaaS products, leading audits, risk and vendor programs, policy management, and AI governance. The role requires 8+ years of GRC experience, expertise in major security frameworks, cloud and AI fluency, and strong cross-functional communication.

Wiz

Wiz

United States

Compliance Engineer - Public Sector
$174k+/yrRemote6+ YOESecurity Engineering

Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.

Snowflake

Snowflake

United States

Senior Security Engineer, Incident Response
$176k+/yrRemote5+ YOESecurity Engineering

Leads product security incident response for Snowflake’s AI and agentic products, developing detection, containment, remediation, and automation capabilities. Requires 5+ years in security, incident command experience, cloud expertise, and knowledge of AI/ML attack surfaces.