Security Engineer, Platform
As a Security Engineer, Platform, you will be responsible for building and improving the security foundations of Resend’s platform, including API keys, service permissions, and secrets management. You will also help design secure defaults for new services and improve detection and response for suspicious access.
About the job
In this role, you will…
- Build and improve the security foundations of Resend’s platform, including API keys, service permissions, secrets management, tenant isolation, audit logs, and internal access controls
- Help design secure defaults for new services, workers, queues, databases, internal tools, and deployment pipelines
- Improve detection and response for suspicious access, leaked credentials, abnormal sending behavior, privilege changes, and sensitive system events
- Review and update our processes/pipelines so that security is “built-in”, not “bolt-on”
- Raise the security bar
You will be a great fit if you...
- Have experience securing production infrastructure, cloud environments, APIs, developer platforms, or multi-tenant SaaS products
- Can write code and are comfortable reading application, infrastructure, and deployment code
- Understand authentication, authorization, secrets, IAM, logging, audit trails, incident response, and secure deployment pipelines.
- Independently prioritize and drive your day-to-day as the first dedicated security hire
- Prefer practical improvements over heavy processes
- Are low-ego, direct, curious, and willing to learn from others
- Care about developer experience and believe security should be easy to adopt
You will be an exceptional fit if you also...
- Have experience with email infrastructure, transactional email, sender reputation, domain verification, SPF, DKIM, DMARC, webhooks, or abuse prevention
- Have secured cloud infrastructure using tools like AWS, Terraform, Kubernetes, Cloudflare, or similar systems
- Have experience with open source security, GitHub organization hardening, package publishing, dependency review, or supply-chain security
- Have helped a company prepare for SOC 2, ISO 27001, GDPR, enterprise security reviews, or customer trust processes without turning engineering into a compliance machine
- Have built security observability, alerting, detection pipelines, or incident response workflows
- Have worked closely with Trust & Safety, anti-abuse, fraud, or platform integrity teams
- Have experience designing security systems for high-scale developer products
What it means to join the team:
- Autonomy to "just ship it"
- 100% remote team with flexible working schedules
- Modern tech stack (Next.js, Raycast, Notion, etc.)
- Honest and low-ego team
- Ownership of problems and solutions
Comp:
$120,000 - $140,000 USD, commensurate with experience
Skills
Api Security, Secrets Management, Tenant Isolation, Audit Logs, Internal Access Controls, Cloud Security, AWS, Terraform, Kubernetes, Cloudflare, Github Security, Supply-Chain Security, SOC 2, ISO 27001, GDPR
Similar jobs
Security Engineering jobsThe Security Engineer will secure AWS and Google Cloud environments, monitor infrastructure, and assess AI/LLM deployments, MCP integrations, and agentic workflows. The role requires 5+ years of security engineering experience, including 2+ years in AI/ML security, plus cloud security and compliance expertise.
The Security Engineer will lead application security across the SDLC, integrating DevSecOps controls, conducting threat modeling and secure code reviews, and managing application vulnerabilities. The role requires 3+ years of application security experience plus hands-on expertise with AWS, Kubernetes, IaC, CI/CD, and mobile or web security.
Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.
The Security GRC Analyst will manage security risks, policies, audits, control testing, and compliance reporting while partnering with technical and business stakeholders. The role requires 4+ years of GRC or security assurance experience and familiarity with major security frameworks.
Own network engineering and government cybersecurity compliance for on-site and field-deployed aerospace systems. The role requires 5+ years of experience, end-to-end IATT/ATO experience, strong networking skills, and familiarity with DoD security frameworks and tactical communications.